Skip to main content

Product Updates

Engine
Surface
AI Workflows
Area
Release Status

Showing 1 - 10 of 73 updates

Announcing Snyk CLI v1.1307.4

Improved

We are pleased to announce Snyk CLI release, v1.1307.4

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • New experimental snyk studio command that sets up Snyk Studio in supported AI coding tools (Cursor, Claude Code, Codex, Copilot, Gemini, Kiro, and Windsurf), so the code they generate gets scanned in the background as it's written. This direct integration replaces the need for separate setup scripts (https://github.com/snyk/studio-recipes). Run snyk studio install --experimental to get started.

  • New snyk fix --agentic filtering flags: --severity-filter to fix only the severities you choose, --breakability-filter to fix only Open Source upgrades with the breakability you choose, and --exclude-ids to fix everything except the issue IDs you list.

  • snyk fix --agentic now keeps a failed fix's changes by default so you can review them, rather than reverting automatically. Pass --enable-revert to restore the automatic rollback behavior.

  • Fixed an issue where the --iac, --docker, --container, and --code flags on snyk test could be silently dropped for organizations on the unified test API, causing scans to fall through to an open-source test instead (which could fail with "No supported files found" or scan the wrong target). These flags now route to the correct scan again.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

A change to the Snyk Code Priority Score

General availability

Snyk Code priority scores dropped by up to 200 points on September 1, 2026, for findings whose rule had a fix example.

What changed

A finding used to earn 200 of the 1,000 available priority score points when Snyk held a fix example for its rule. The August 17, 2026 release retired fix examples, and the scoring factor went with them. The removal became live on September 1, 2026.

Why

Fix-example availability describes Snyk's content coverage. It says nothing about the risk in your code. Two findings of the same severity could sit 200 points apart because one rule happened to have an example behind it. Priority score should rank findings by how urgently they need fixing, so we removed the factor.

What you saw

Snyk Code findings reordered when the factor came out. Every remaining scoring factor works as it did before, including severity, which still contributes the largest single share at up to 500 points. No finding was added, removed or re-rated.

We should have told you

The August 17 release notes said no action was required. That was wrong, and we apologize. We have added a check so that any future change to priority score appears in the release notes. The priority score documentation now lists the current factors.

Learn more in the Snyk Code priority score documentation.

Headshot of Sebastian Roth

Sebastian Roth | Senior Product Manager

Announcing Snyk CLI v1.1307.3

Fix

We are pleased to announce Snyk CLI release, v1.1307.3

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • snyk test now reports an unreadable .snyk policy file as SNYK-POLICY-0002 with a message identifying the problem, instead of an unspecified error.

  • snyk test --all-projects now resolves each project's .snyk policy from that project's own directory, instead of applying the scan root's policy to every project.

  • snyk test --scan-all-unmanaged no longer fails with exit code 2 when scanning a directory of JARs with no manifest file.

  • Fixed vulnerabilities:

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Tags:

Container: Go standard library vulnerability reporting

General availability

Snyk Container will begin reporting vulnerabilities from the Go standard library for all customers. Scans of container images built from Go binaries identify the standard library version the binary was compiled with and report known vulnerabilities against it.

Affected images gain a new stdlib dependency in the dependency graph, versioned to the Go release used for the build, for example stdlib@1.25.10. Detection works for standard, stripped, and CGo builds.

No configuration is required, and reporting is enabled automatically for all organizations. Standard library reporting in the Snyk CLI requires v1.1303.2 or later.

This change is scheduled to take effect on October 7, 2026.

Snyk Container reported vulnerabilities in third-party Go dependencies, but not in the Go standard library itself, the HTTP, TLS, JSON, and other libraries that ship with the Go toolchain rather than being installed as dependencies. Those vulnerabilities were visible only indirectly, through distro advisories, so teams shipping Go binaries in containers had no reliable way to see them.

That left two gaps: one between what Snyk Container reported and what Snyk Open Source already reported for the same code, and one in real coverage for any Go application running in a container - this change closes both.

If you scan container images built from Go binaries, your vulnerability counts will increase. Each affected project gains a fixed number of new findings, determined by the Go version the binary was built with. Older Go releases carry more.

Building with a current Go patch release substantially reduces or eliminates these findings. Images built with Go 1.25.13 or later, or Go 1.26.6 or later, report no new vulnerabilities from this change. We recommend reviewing the Go versions used in your build pipelines ahead of the release date.

Considerations and known limitations:

  • Snyk does not perform reachability analysis on standard library packages. Snyk reports all known vulnerabilities for the standard library version in your binary, rather than only those in packages your code imports. This is consistent with the approach taken by other container scanners.

  • Findings that are not relevant to your application can be ignored in Snyk as usual

For more information, see Application vulnerabilities in Snyk Container and Snyk Open Source in the Snyk user documentation: https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/application-vulnerabilities-in-snyk-container-and-snyk-open-source

Announcing Snyk CLI v1.1307.2

Fix

We are pleased to announce Snyk CLI release, v1.1307.2

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Removed an unused experimental feature.

  • Fixed vulnerabilities:

    • CVE-2026-84445

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Tags:

Announcing Snyk CLI v1.1307.1

Fix

We are pleased to announce Snyk CLI release, v1.1307.1

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • snyk test again reports SNYK-CLI-0008 and exits with code 3 when a repository contains no supported manifest files, instead of a generic SNYK-CLI-0000 with exit code 2. snyk test --json writes the error document to stdout as expected.

  • Restored the moduleName, insights.triageAdvice, and functions_new fields in snyk test --json output, so tooling that consumes those fields works as before.

  • .snyk policy files are now handled correctly in the unified test flow. This covers empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that could previously cause incorrect results or failures.

  • Commands that complete with findings (exit code 1) no longer produce duplicate or corrupt JSON output when an unrelated network error occurs during the run, improving reliability for automated pipelines that parse CLI output.

  • The debug-log scrubber now masks secrets consistently and no longer corrupts the surrounding JSON structure, making debug logs safer to share and easier to parse.

  • Container scans now surface source repository information for locally built images using BuildKit metadata.

  • Fixed vulnerabilities:

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Announcing Snyk CLI v1.1307.0

Improved

We are pleased to announce the latest stable Snyk CLI release, v1.1307.0.

We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Secrets

    • snyk secrets test now supports exclusions — add files or paths to the exclude section of your .snyk file to skip them during secrets scanning.

  • Container

    • Container scans now surface image provenance attestations by default, so signed-image provenance metadata appears in results without any extra flag.

  • .NET/NuGet

    • snyk test can now analyze already-restored .NET/NuGet projects fully offline and no longer requires .NET 6 to be installed.

  • MCP

    • The full Snyk MCP profile now includes Snyk Secrets.

  • Code & Secrets

    • SARIF suppressions now include reviewedOn and reviewedBy metadata.

  • AI BOM

    • snyk aibom test --severity-threshold now filters the displayed and JSON results by severity, not only the exit code.

  • Agent-optimized CLI

    • New experimental snyk agent command space — a scanning surface built for AI coding agents, with token-optimized output and ergonomics. snyk agent test runs Snyk Open Source, Code, and Secrets together.

  • Additional Reliability and Performance Improvements

    • Adds support for scanning pnpm v11 pnpm-lock.yaml lockfiles.

    • Fixes a crash when scanning dependencies of Gradle 7.4–8.2 projects.

    • Fixes a bug where arguments after -- (for example snyk test . -- -s settings.xml) were treated as scan targets, which could silently drop the Risk Score.

    • Fixes scanning of projects using Hex versions newer than 1.19.

    • Excludes the .git folder from file discovery, preventing intermittent scan failures caused by changes to .git contents during a scan

    • Prevents a possible connection leak when the Snyk API returns an error response.

    • Updates dependencies to fix vulnerabilities.

Release notes can be found here.

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.

Matt Dolan | Senior Product Manager

New model risk scoring for AI models in Evo

General availability

Starting August 17, 2026, Evo by Snyk uses a rebuilt model risk score to evaluate the AI models discovered in your organization.

The previous Risk Index is replaced by a single score from 0–1,000 that combines attack success rate with the potential impact of a successful attack, tested against categories including prompt injection, data exfiltration, and insecure code generation. The result is a score that reflects both how easily a model can be compromised and how much damage that compromise could cause — not just whether an attack succeeded.

What's new:

  • Impact-weighted scoring: Risk scores now factor in the real-world consequence of an attack succeeding, not only its likelihood.

  • Four severity bands: Scores map to low (0–249), medium (250–499), high (500–749), and critical (750–1,000), so you can triage at a glance.

  • Broader attack coverage: Testing spans a wider range of direct and indirect attack categories against each discovered model.

  • Framework-mapped: Findings map to OWASP LLM Top 10, OWASP Agentic Security, MITRE ATLAS, and NIST AI 600-1/100-2e2025, so you can connect model risk to the compliance frameworks you already report against.

  • Policy-ready from day one: Evo applies default policies across common attack categories automatically, and you can create custom policies scoped to specific attack categories or goals to match your organization's risk tolerance.

If you have policies built on the old Risk Index: those policies remain visible but no longer evaluate under the new scoring. Review and recreate any Risk Index-based policies against the new model risk score to keep enforcement active.

Read more in the Risk intelligence documentation.

Headshot of Ranko Cupovic

Ranko Cupovic | Principal Product Manager

Announcing Snyk CLI v1.1306.4

Fix

We are pleased to announce Snyk CLI release, v1.1306.4

This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Clearer error messages when the CLI cannot reach a configured proxy. Failures now report the proxy URL the CLI attempted to use, with credentials redacted, along with the specific error code SNYK-CLI-0028, making proxy misconfiguration quicker to diagnose in CI and behind corporate networks.

  • An updated embedded runtime, moving Node.js from 22.22.2 to 22.23.2 and OpenSSL from 3.5.5 to 3.5.7, which brings in fixes for six high-severity CVEs plus additional OpenSSL security fixes.

  • Fixed vulnerabilities:

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Tags:

Announcing Snyk CLI v1.1306.3

Fix

We are pleased to announce Snyk CLI release, v1.1306.3

This release contains security fixes. To learn more beyond what is highlighted below, please reference the full release notes.

This update includes the following:

  • Updates bundled dependencies to remediate known vulnerabilities, keeping the CLI current for teams with supply chain policies on the tools running in their pipelines.

  • Fixed vulnerabilities:

If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.

Matt Dolan | Senior Product Manager

Tags: