Announcing Snyk CLI v1.1308.0
We are pleased to announce the latest stable Snyk CLI release, v1.1308.0.
We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.
This update includes the following:
HTML Reports
snyk test,snyk code testandsnyk secrets testcan now generate an HTML report. Use--htmlto print it to stdout, or--html-file-output=<path>to write it to a file. This replaces the need for a separate snyk-to-html tool in most cases.
Agent Scan (experimental)
The experimental
snyk agent-scancommand now reports risk indicators instead of issue codes. If you post-process its--jsonoutput, update your scripts to the new format.
Additional Reliability and Performance Improvements
Maven and Gradle SBOMs, and
--print-graph, no longer stall on large multi-module builds and now finish seconds after the build tool exits. On projects with dependency cycles, the output may contain extrapruned: cyclicplaceholder nodes. No packages or dependency edges are dropped.Gradle projects with very deep inter-module dependency chains no longer fail with a stack overflow.
Projects built with Gradle 4.0 to 4.6 no longer fail to scan.
.NET scans fall back to legacy scanning when the .NET SDK isn't installed. They also handle projects restored in a different build directory, and work when global NuGet source-mapping rules are configured.
.NET scans no longer fail with
NU1101on SDK installs that lack the app host pack, such as distro-packaged SDKs..NET projects whose
PackageReferenceuses a lowercaseversionattribute are now parsed correctly.Updates dependencies to fix vulnerabilities
Release notes can be found here.
If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.
Matt Dolan | Senior Product Manager