<?xml version="1.0" encoding="UTF-8"?>

    <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
      <channel>
        <title>snyk.io updates</title>
        <link>https://updates.snyk.io</link>
        <description>snyk.io updates</description>
        <language>en-us</language>
        <lastBuildDate>Thu, 23 Apr 2026 07:38:47 GMT</lastBuildDate>
        <atom:link href="https://updates.snyk.io/rss" rel="self" type="application/rss+xml" />
        
        <item>
          <title>Announcing Repo Monitor Configuration</title>
          <link>https://updates.snyk.io/announcing-repo-monitor-configuration/</link>
          <description>&lt;p&gt;We are excited to be launching Repo Monitor Configuration, which allows for management of repository coverage and monitoring configurations centrally across your entire Snyk Group from the Group-level Inventory page. This means you can monitor and manage repositories without navigating between individual Snyk Organizations.&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;https://docs.snyk.io/manage-assets/configure-repository-monitoring&quot;&gt;Repo Monitor Configuration&lt;/a&gt; provides the following capabilities:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Centralized asset monitoring: view monitoring status for all products, identify health status, and see required actions (such as enabling Snyk Code or resolving SCM integration issues) in one view.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Bulk import: import repositories directly from the Group Inventory page into specific Snyk Organizations.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;On-demand retesting: trigger a retest for specific repositories directly from Inventory.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Actionable error resolution: clear guidance ia available when testing fails due to integration issues or entitlements. After the underlying issue is resolved, testing resumes automatically.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</description>
          <pubDate>Wed, 15 Apr 2026 05:00:00 GMT</pubDate>
          <dc:creator>Nathan Hart, Senior Product Manager</dc:creator>
          <guid>3KPHj6ERKAN51pWnXwBghn</guid>
          <category>Early access</category>
        </item>
        <item>
          <title>Repo Content Sync in Early Access</title>
          <link>https://updates.snyk.io/repo-content-sync-in-early-access/</link>
          <description>&lt;p&gt;We are excited to be launching Repository Content Sync (Early Access), an enhancement to how Snyk manages your imported repositories, ensuring your security posture always reflects your current codebase.  This will be available to all Enterprise customers via Snyk Preview during the week of April 13th, 2026.&lt;/p&gt;&lt;p&gt;This new feature provides native, automated synchronization between your Source Code Management (SCM) tool and Snyk, eliminating the need for manual re-imports or external synchronization tools. It ensures:
New Files are Detected: Snyk automatically creates new projects and monitors manifest, Docker, or configuration files as they are added to your SCM.
Deletions are Reflected: Projects associated with manifest files deleted in your SCM are automatically deactivated in Snyk.
This functionality is available across all Snyk-supported SCMs.&lt;/p&gt;&lt;p&gt;Please note: Because this feature enables Snyk to automatically detect and potentially create projects from newly added files, customers who enable the feature are likely to see an increase in issues.&lt;/p&gt;</description>
          <pubDate>Mon, 13 Apr 2026 23:00:00 GMT</pubDate>
          <dc:creator>Nathan Hart, Senior Product Manager</dc:creator>
          <guid>5rWKMfxyltIo3mLMn7dOYU</guid>
          <category>Early access</category>
        </item>
        <item>
          <title>Announcing new versions of Snyk IDE plugins</title>
          <link>https://updates.snyk.io/announcing-new-versions-of-snyk-ide-plugins/</link>
          <description>&lt;p&gt;We are pleased to announce the release of new stable versions for our IDE plugins. 
The new versions are:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://marketplace.visualstudio.com/items?itemName=snyk-security.snyk-vulnerability-scanner&amp;ssr=false#version-history&quot;&gt;&lt;u&gt;Visual Studio Code v2.31.0&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://plugins.jetbrains.com/plugin/10972-snyk-security/versions/stable&quot;&gt;&lt;u&gt;JetBrains v2.21.0&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://marketplace.eclipse.org/content/snyk-security&quot;&gt;&lt;u&gt;Eclipse v3.9.0&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://marketplace.visualstudio.com/items?itemName=snyk-security.snyk-vulnerability-scanner-vs-2022&quot;&gt;&lt;u&gt;Visual Studio v2.9.0&lt;/u&gt;&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This release is focused on enhancing stability and reliability, with key updates including:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Fixed download URL fallback when the CLI is not found&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed race conditions in authentication flows&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Added support for JetBrains 2026.1&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Along with additional bug fixes, security updates, and improvements.&lt;/p&gt;&lt;p&gt;Please refer to the changelog for each of our plugins for a more detailed list of additional bug fixes and enhancements. You can learn more about the Snyk IDE plugins in our &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-in-an-ide/&quot;&gt;&lt;u&gt;Learn resources&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk Support team.&lt;/p&gt;</description>
          <pubDate>Sun, 12 Apr 2026 23:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>5GmrezRhx6xBrMazqxo4Oy</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Native GraphQL Scanning for Snyk API &amp; Web</title>
          <link>https://updates.snyk.io/native-graphql-scanning-for-snyk-api-and-web/</link>
          <description>&lt;p&gt;We’ve expanded our DAST capabilities by adding GraphQL as a supported API target type in Snyk API &amp;amp; Web. This enables security tests specifically designed for GraphQL operations, including queries and mutations. In addition to schema ingestion via URL or file upload, you can now fetch your schema directly from an introspection endpoint to ensure tests stay up to date. To support these scans, we&amp;#39;ve also updated our authentication settings to include dedicated options for GraphQL targets.&lt;/p&gt;</description>
          <pubDate>Fri, 10 Apr 2026 08:00:00 GMT</pubDate>
          <dc:creator>Natalia Yurchenko, Senior Product Manager</dc:creator>
          <guid>4vNMGApPmLFI4YUjTCMhTE</guid>
          <category>New</category>
        </item>
        <item>
          <title>Test target configuration for smoother scans with Snyk API &amp; Web</title>
          <link>https://updates.snyk.io/test-target-configuration-for-smoother-scans-with-snyk-api-and-web/</link>
          <description>&lt;p&gt;We added a new &lt;b&gt;Test configuration&lt;/b&gt; option to the &lt;b&gt;Scan&lt;/b&gt; dropdown menu and the &lt;b&gt;Target Settings&lt;/b&gt; page. This allows you to verify that your target is accessible and correctly configured before starting a full dynamic application security testing (DAST) scan. When you click this button, a side panel opens in your target settings to provide real-time feedback on connectivity, authentication, web application firewall (WAF) interference, schema validity, and any detected extra hosts.&lt;/p&gt;</description>
          <pubDate>Thu, 09 Apr 2026 14:00:00 GMT</pubDate>
          <dc:creator>Ana Pascoal, Product Manager</dc:creator>
          <guid>6aOCg6BOgP7nKb86O7RPdr</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Announcing native uv support for the Snyk CLI</title>
          <link>https://updates.snyk.io/announcing-native-uv-support-for-the-snyk-cli/</link>
          <description>&lt;p&gt;Python is at the heart of the modern AI revolution but for many developers the packaging ecosystem has felt like a bottleneck: burdened by slow installs and fragmented tooling. The emergence of &lt;code&gt;uv&lt;/code&gt; has changed that, offering a high-performance alternative that has quickly become the industry standard.&lt;/p&gt;&lt;p&gt;Today, we are excited to announce that Snyk is bringing &lt;b&gt;native support for &lt;/b&gt;&lt;code&gt;&lt;b&gt;uv&lt;/b&gt;&lt;/code&gt; to the Snyk CLI, IDE, and GitHub Actions. This integration ensures that teams can embrace the speed of &lt;code&gt;uv&lt;/code&gt; without ever having to trade off on security.&lt;/p&gt;&lt;p&gt;With this update, Snyk enables you to seamlessly integrate &lt;code&gt;uv&lt;/code&gt; security scanning directly into your existing Snyk workflows, wherever you are using the CLI.&lt;/p&gt;</description>
          <pubDate>Thu, 09 Apr 2026 12:30:00 GMT</pubDate>
          <dc:creator>Johann Sutherland, undefined</dc:creator>
          <guid>3Oqvg6ec7R73azkArYETHQ</guid>
          <category>Early access</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1304.0</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1304-0/</link>
          <description>&lt;p&gt;We are pleased to announce the latest stable Snyk CLI release, v1.1304.0.&lt;/p&gt;&lt;p&gt;We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Snyk Evo&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Accelerate AI Governance and Security: Generate an AI-BOM and instantly validate it against your tenant&amp;#39;s Evo policies using the new &lt;a href=&quot;https://docs.snyk.io/developer-tools/snyk-cli/commands/aibom-test&quot;&gt;&lt;u&gt;snyk aibom test&lt;/u&gt;&lt;/a&gt; command.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Enhanced Red Teaming insights: Agent Red Teaming scanned output now includes a vulnerability summary for quicker triage. Also improved JSON support and new exhaustive and eager modes.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Faster setup: Improved auto-enable behavior for Snyk Code.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Ensure Reliable Package Quality: Package health checks are now fully promoted to the stable release channel, providing consistent and reliable risk information.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Container&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Extended support for Java runtime binary scanning.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Additional Reliability and Performance Improvements&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Increased stability with explicit network retry configuration, option to force global Maven usage, faster Golang scans, improved dependency resolution for Go, Yarn, and Python, and enhanced resilience against non-fatal Maven build errors.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Release notes can be found &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1304.0&quot;&gt;&lt;u&gt;here&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.&lt;/p&gt;</description>
          <pubDate>Wed, 08 Apr 2026 23:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>7ra2PVrDiV8YJCnqsLguAT</guid>
          <category>New</category>
        </item>
        <item>
          <title>snyk_package_health_check for Snyk Studio is now available in Full profile</title>
          <link>https://updates.snyk.io/snyk_package_health_check-for-snyk-studio-is-now-available-in-full-profile/</link>
          <description>&lt;p&gt;Following our &lt;a href=&quot;https://updates.snyk.io/announcing-snyk_package_health_check-for-snyk-studio/&quot;&gt;&lt;u&gt;previous announcement&lt;/u&gt;&lt;/a&gt;, &lt;code&gt;snyk_package_health_check&lt;/code&gt; is now available in the Full (default) profile for Snyk MCP.&lt;/p&gt;&lt;p&gt;This capability brings Secure at Inception protection to dependency selection in agentic development workflows, enabling AI agents to evaluate open-source packages before they are added to a project using insights from &lt;a href=&quot;https://security.snyk.io/&quot;&gt;Snyk’s Security Database&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;code&gt;snyk_package_health_check&lt;/code&gt; is now generally available and enabled by default for supported ecosystems: npm, PyPI, Maven, NuGet, and Golang.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What’s new&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Now included in the Full (default) profile - &lt;code&gt;snyk_package_health_check&lt;/code&gt; is enabled by default for Snyk-supported MCP workflows.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Package health checks across four dimensions: Security, Maintenance, Community, and Popularity.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Clear guidance outcomes to help manage agent behavior, including Healthy, Review recommended, Not recommended, and Unknown/insufficient data.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Why this matters&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Available by default - &lt;code&gt;snyk_package_health_check&lt;/code&gt; is now included in the Full profile, so customers get dependency health checks in MCP workflows without additional setup.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Ready for production use - With this move to the Full profile, customers can confidently integrate Secure at Inception into their standard development workflows.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, please reach out to the Snyk Support team. To learn more about &lt;code&gt;snyk_package_health_check&lt;/code&gt;, visit the &lt;a href=&quot;https://docs.snyk.io/integrations/snyk-studio-agentic-integrations/getting-started-with-snyk-studio&quot;&gt;&lt;u&gt;Snyk documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Tue, 07 Apr 2026 21:00:00 GMT</pubDate>
          <dc:creator>Noa Yaffe-Ermoza, Product Manager</dc:creator>
          <guid>1wTXyoidtYG3cpziIrps5o</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>PR check report is now generally available</title>
          <link>https://updates.snyk.io/pr-check-report-is-now-generally-available/</link>
          <description>&lt;p&gt;We’ve moved the pull request (PR) check report to general availability (GA). This update includes several enhancements to help you track how your teams adopt security scanning within their workflows. We added Snyk Code errors to the error PR checks, fixed historical calculation discrepancies in adoption metrics, and optimized the underlying tables so that all reporting components load and filter much faster. Additionally, we updated the display of source code manager (SCM) icons to better organize the PR scanning adoption by organization table, and we added PR check data to the Export application programming interface (API), enabling you to programmatically export this information.&lt;/p&gt;</description>
          <pubDate>Tue, 07 Apr 2026 04:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>32Wfvnq5CF1OHXAjYrDY0N</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Introducing Unified Navigation: A Faster Way to Secure Your Application Stack</title>
          <link>https://updates.snyk.io/introducing-unified-navigation-a-faster-way-to-secure-your-application-stack/</link>
          <description>&lt;h2&gt;Key Capabilities of Unified Navigation&lt;/h2&gt;&lt;p&gt;&lt;b&gt;1. A Single Source of Truth&lt;/b&gt; The new navigation bar consolidates all Snyk products—Code, Container, IaC, and Cloud—into one sidebar. You can now access the global search to find any project or issue across your entire organization instantly.&lt;/p&gt;&lt;p&gt;&lt;b&gt;2. Context-Aware Shortcuts&lt;/b&gt; Snyk now recognizes what you are working on and provides intelligent shortcuts. This reduces the steps for common workflows from 8 clicks down to just 2 or 3, allowing you to move at the speed of development.&lt;/p&gt;&lt;p&gt;&lt;b&gt;3. Developer-First Interface &lt;/b&gt;We’ve redesigned the experience to match how developers actually work. This includes &lt;b&gt;Persistent Views; &lt;/b&gt;the platform now remembers your filters and workspace settings, so you don&amp;#39;t have to rebuild them every time you log in.&lt;/p&gt;&lt;p&gt;&lt;b&gt;4. Simplified Project Management&lt;/b&gt; Setting up new scans is now more intuitive. With a visual policy builder and templates, you can configure security rules without editing complex YAML files.&lt;/p&gt;</description>
          <pubDate>Mon, 06 Apr 2026 21:00:00 GMT</pubDate>
          <dc:creator> Maor Kuriel, Director of Product</dc:creator>
          <guid>5HmEysG9EAZbrkhNurTNiy</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Automatically Close Obsolete Fix Open Source PRs with Help from Snyk</title>
          <link>https://updates.snyk.io/automatically-close-obsolete-fix-open-source-prs-with-help-from-snyk/</link>
          <description>&lt;p&gt;Nobody likes a cluttered PR backlog. That&amp;#39;s why Snyk now automatically closes Open Source Fix PRs if the vulnerabilities they target are no longer present in your project.&lt;/p&gt;&lt;p&gt;Whether a developer manually applied a fix, removed the dependency, or a transitive update resolved the issue, Snyk will catch it during your next recurring test and close the outdated PR. We will also drop a comment on the PR explaining exactly which issues were resolved, ensuring your team always has the right context without the extra noise.&lt;/p&gt;&lt;p&gt;&lt;b&gt;How it works:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Snyk checks your open Fix PRs during your regular recurring tests.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;If the targeted issues are gone—whether the dependency was removed, updated transitively, or fixed manually—the PR is automatically closed.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Snyk leaves a comment on the PR listing the resolved issues so your team knows exactly why it was closed.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This update gives you a cleaner, more actionable PR pipeline with zero extra effort.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Get Started Today&lt;/b&gt; This feature is going live as an opt-in starting today. Just navigate to the Snyk Preview panel to get started, and we&amp;#39;ll begin closing up to five obsolete PRs from your backlog per day. As we move towards General Availability, we&amp;#39;ll be bringing you the ability to configure that daily limit to best suit your team&amp;#39;s workflow. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Please note&lt;/b&gt; that this feature is opt-in for Early Access, but once we move to General Availability, it will move to opt-out. This feature is tentatively scheduled to move to General Availability on June 15, 2026.&lt;/p&gt;&lt;p&gt;And stay tuned—there is a lot more to come in our ongoing efforts to revolutionize the Snyk PR experience!&lt;/p&gt;&lt;p&gt;&lt;/p&gt;</description>
          <pubDate>Mon, 06 Apr 2026 04:00:00 GMT</pubDate>
          <dc:creator> Ryan McMorrow, Product Lead, Remediation</dc:creator>
          <guid>3PED1oWeSVBLWRAr6Tp7Jg</guid>
          <category>Early access</category>
        </item>
        <item>
          <title>Active Security Incident Assessment</title>
          <link>https://updates.snyk.io/active-security-incident-assessment/</link>
          <description>&lt;p&gt;We’ve launched an Active security incident assessment banner to help you manage major zero-day events. When our Security team identifies a high-severity zero-day vulnerability in a widely used package, we’ll trigger a dedicated banner at the top of the Zero Day report. This assessment provides a look at your exposure, including the total number of assets needing triage, assets cleared, and the specific open-source (OSS) packages involved. &lt;/p&gt;</description>
          <pubDate>Fri, 03 Apr 2026 04:00:00 GMT</pubDate>
          <dc:creator>Sara Meadzinger, Staff Product Manager</dc:creator>
          <guid>5w4nNR9ajDAP6qIlf9cTN8</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Snyk Learn lesson roundup: what’s new in April</title>
          <link>https://updates.snyk.io/snyk-learn-lesson-roundup-whats-new-in-april/</link>
          <description>&lt;p&gt;We’ve added new secure coding content, Snyk platform training, and expanded Snyk Learn coverage to help your security engineers and developers stay ahead of the latest risks.&lt;/p&gt;&lt;p&gt;We’ve included direct links to every new and updated lesson so you can easily share them with your team. You can also assign them directly through the &lt;a href=&quot;https://docs.snyk.io/discover-snyk/snyk-learn#learning-management-add-on&quot;&gt;Snyk Learning Management Add-On&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Security lessons&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;We are creating lessons for the new &lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;OWASP Top 10 for Agentic Applications&lt;/a&gt;, with the first 4 lessons available.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/agent-goal-hijack/&quot;&gt;Agentic 01 - Agent goal hijack&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/agent-tool-misuse-and-exploitation/&quot;&gt;Agentic 02 - Agent tool misuse&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt;&lt;a href=&quot;https://learn.snyk.io/lesson/agentic-identity-and-privilege-abuse/&quot;&gt; Agentic 03 - Identity and privilege abuse&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/agentic-supply-chain-vulnerabilities/&quot;&gt;Agentic 04 - Agentic supply chain vulnerabilities&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/cross-origin-resource-sharing&quot;&gt;Cross-origin resource sharing&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Snyk platform lessons&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[New]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/review-credit-consumption-for-billing/?ecosystem=general&quot;&gt;Snyk Billing and Credit Usage&lt;/a&gt; - a new lesson on how credits function within the Snyk platform and how to track and manage them in the Billing module.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;We have refreshed the following lessons to ensure all content reflects our current platform and products, also providing a streamlined learning experience:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt;&lt;a href=&quot;https://learn.snyk.io/lesson/issue-prioritization/?ecosystem=general&quot;&gt; Prioritizing issues with Snyk &lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-and-snyk-apprisk-integrations/?ecosystem=general&quot;&gt;Integrations for asset management and discovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-and-snyk-apprisk-inventory/?ecosystem=general&quot;&gt;Reviewing Inventory for asset management and discovery &lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-asset-dashboard/?ecosystem=general&quot;&gt;Asset Dashboard report for asset management and discovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-and-snyk-apprisk-policies/?ecosystem=general&quot;&gt;Policies for asset management and discovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-and-snyk-apprisk-overview/?ecosystem=general&quot;&gt;Overview of Snyk for asset management and discovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-and-snyk-apprisk-terminology/?ecosystem=general&quot;&gt;Snyk terminology for asset management and discovery&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-apprisk-application-analytics/?ecosystem=general&quot;&gt;Snyk Platform using Snyk Analytics&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-servicenow-cmdb-application-context/?ecosystem=general&quot;&gt;Application context with ServiceNow® CMDB&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;[Updated]&lt;/b&gt; &lt;a href=&quot;https://learn.snyk.io/lesson/snyk-essentials-backstage-software-catalog-application-context/?ecosystem=general&quot;&gt;Application context with Backstage software catalog&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Expanded framework &amp;amp; language coverage&lt;/h3&gt;&lt;p&gt;We’ve also expanded Snyk Learn content to cover more of your tech stack:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;We have added support to almost &lt;a href=&quot;https://learn.snyk.io/catalog/?type=security-education&amp;categories=ruby&quot;&gt;50 lessons for Ruby&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;We have added support to &lt;a href=&quot;https://learn.snyk.io/catalog/?type=security-education&amp;categories=rust&quot;&gt;30 lessons for Rust&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</description>
          <pubDate>Wed, 01 Apr 2026 15:00:00 GMT</pubDate>
          <dc:creator>Alex Ley, Director, Snyk Learn</dc:creator>
          <guid>sq5d2vaFDgypnWTfwKHxf</guid>
          <category>New</category>
        </item>
        <item>
          <title>Enhanced issue filtering for the export API</title>
          <link>https://updates.snyk.io/enhanced-issue-filtering-for-the-export-api/</link>
          <description>&lt;p&gt;We&amp;#39;re updating the stable Export API (version 2024-10-15) to include more granular filtering for the issues dataset. You can now filter your export request payloads using additional parameters, including issue status, issue type, and project origin. We&amp;#39;ve also added support for advanced filters such as common vulnerabilities and exposures (CVE) ID, reachability, and National Vulnerability Database (NVD) severity to help you refine your reporting.&lt;/p&gt;</description>
          <pubDate>Tue, 31 Mar 2026 04:00:00 GMT</pubDate>
          <dc:creator>Sara Meadzinger, Staff Product Manager</dc:creator>
          <guid>6ZPjxbTT027PpuL3kZD3Yz</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Track your monitored projects with a new analytics widget</title>
          <link>https://updates.snyk.io/track-your-monitored-projects-with-a-new-analytics-widget/</link>
          <description>&lt;p&gt;We’re adding an analytics overview widget that tracks the total number of Snyk projects being monitored. This key performance indicator (KPI) is available in the &lt;b&gt;Widget selector&lt;/b&gt;, allowing you to add it to your saved dashboards. This update helps you visualize the total count of projects being continuously monitored for open-source vulnerabilities and license issues, after you use the &lt;code&gt;snyk monitor&lt;/code&gt; command.&lt;/p&gt;</description>
          <pubDate>Tue, 31 Mar 2026 04:00:00 GMT</pubDate>
          <dc:creator>Sara Meadzinger, Staff Product Manager</dc:creator>
          <guid>3xRhVOm1VNW4qJkqqDfKaG</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Updates to finding management permissions at Snyk API &amp; Web</title>
          <link>https://updates.snyk.io/updates-to-finding-management-permissions-at-snyk-api-and-web/</link>
          <description>&lt;p&gt;We&amp;#39;re introducing a new permission called &lt;b&gt;Change Finding State&lt;/b&gt; to give you more granular control over how your teams manage security findings. Previously, the &lt;b&gt;Change Finding&lt;/b&gt; permission covered several actions: changing a finding&amp;#39;s state, review status, assignee, labels, and adding notes. We&amp;#39;ve separated these capabilities so that &lt;b&gt;Change Finding State&lt;/b&gt; now specifically handles changing a finding&amp;#39;s state and review status, and the existing &lt;b&gt;Change Finding&lt;/b&gt; permission now focuses on managing assignees, labels, and notes. To prevent any workflow interruptions, all built-in and existing custom roles that currently have the &lt;b&gt;Change Finding&lt;/b&gt; permission will automatically receive the new &lt;b&gt;Change Finding State&lt;/b&gt; permission.&lt;/p&gt;</description>
          <pubDate>Mon, 30 Mar 2026 10:15:00 GMT</pubDate>
          <dc:creator>Ana Pascoal, Product Manager</dc:creator>
          <guid>1q3RVY7eG18gRMFO1ccZdG</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Export table data to CSV with Snyk API &amp; Web</title>
          <link>https://updates.snyk.io/export-table-data-to-csv-with-snyk-api-and-web/</link>
          <description>&lt;p&gt;We’re introducing a new &lt;b&gt;Download CSV&lt;/b&gt; feature to help you export your data directly from the interface. Starting today, you can download a comma-separated values (CSV) file that matches your current table view, including any active filters or hidden columns. We&amp;#39;ll follow this implementation soon after, with an enhanced version that gives you even more flexibility, by allowing you to choose from a wider range of fields, which ones to include in your CSV file. &lt;/p&gt;</description>
          <pubDate>Mon, 30 Mar 2026 10:15:00 GMT</pubDate>
          <dc:creator>Ana Pascoal, Product Manager</dc:creator>
          <guid>78wRxH1qRgLpDM8t85KvyS</guid>
          <category>New</category>
        </item>
        <item>
          <title>SPDX License List Updated to v3.28</title>
          <link>https://updates.snyk.io/spdx-license-list-updated-to-v3-28/</link>
          <description>&lt;p&gt;We’ve updated Snyk Open Source license detection to use the latest  &lt;a href=&quot;https://spdx.org/licenses/&quot;&gt;&lt;u&gt;SPDX license list &lt;/u&gt;&lt;/a&gt; (v3.28), upgrading from the previously supported version (v3.20). &lt;/p&gt;&lt;p&gt;This update improves license recognition across dependencies and reduces the number of licenses previously categorized as “Unknown”. With this change, Snyk can now recognize and surface additional standard SPDX licenses, enabling more accurate license compliance insights and allowing customers to define policies for these licenses directly.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What’s changed&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Updated SPDX License List support to the latest version, v3.28 (previously v3.20).&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Snyk Open Source license detection now recognizes additional SPDX licenses included in the latest version.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Newly recognized licenses can now be managed in License Policies, reducing cases where licenses appear as “Unknown.”&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Who’s affected&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;This update applies to all customers using Snyk Open Source license scanning.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Newly supported licenses will appear after the next dependency scan or project re-test.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Why this matters&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Previously, some dependencies using valid SPDX licenses were categorized as “Unknown” because they were not yet supported by Snyk.&lt;/p&gt;&lt;p&gt;By expanding SPDX license coverage, this update helps teams:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Improve the accuracy of license detection in dependency scans.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Define policies for a broader set of open source licenses.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Reduce manual investigation when licenses appear as “Unknown”.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions about this update, please reach out to the Snyk Support team.&lt;/p&gt;&lt;p&gt;To learn more about licenses, visit the &lt;a href=&quot;https://docs.snyk.io/scan-with-snyk/snyk-open-source/scan-open-source-libraries-and-licenses/open-source-license-compliance#license-updates&quot;&gt;&lt;u&gt;Snyk documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Sun, 29 Mar 2026 21:00:00 GMT</pubDate>
          <dc:creator>Noa Yaffe-Ermoza, Product Manager</dc:creator>
          <guid>KeXjEnD1UNIBwhDebcj2H</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Improved License Policy Behavior for Newly Added Licenses</title>
          <link>https://updates.snyk.io/improved-license-policy-behavior-for-newly-added-licenses/</link>
          <description>&lt;p&gt;We’ve updated how newly supported licenses behave in &lt;a href=&quot;https://docs.snyk.io/manage-risk/policies/license-policies/create-a-license-policy-and-rules&quot;&gt;&lt;u&gt;Snyk Open Source license policies&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;When Snyk adds support for new licenses, they will now default to a severity of None and will not inherit the severity configured for the Unknown license type.&lt;/p&gt;&lt;p&gt;As a result, newly supported licenses will not generate findings unless a severity is explicitly configured in your License Policy.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What’s changed&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Newly added licenses now default to severity = None.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Newly added licenses do not inherit the severity configured for the Unknown license type.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;These licenses will only generate findings if a severity is explicitly configured in your License Policy. These licenses will still be detected and visible in SBOMs and in your Project’s dependency data. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;You can review and configure severity levels for newly supported licenses directly in your License Policies.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Why this matters&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;This change makes license policy behavior more predictable and gives you full control over how newly supported licenses are classified.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Previously, newly added licenses could inherit the severity configured for the Unknown license type, leading to unexpected findings when new licenses were introduced.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Recommended action&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;If you rely on license policies to flag licenses in scan results, we recommend periodically reviewing your License Policies and assigning severity levels to newly supported licenses that are relevant to your organization.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions about this change, please reach out to the Snyk Support team.&lt;/p&gt;&lt;p&gt;To learn more about licenses, visit the &lt;a href=&quot;https://docs.snyk.io/manage-risk/policies/license-policies/create-a-license-policy-and-rules&quot;&gt;&lt;u&gt;Snyk documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Sun, 29 Mar 2026 21:00:00 GMT</pubDate>
          <dc:creator>Noa Yaffe-Ermoza, Product Manager</dc:creator>
          <guid>HuoYskeWPSmVTXEu1fYf3</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Snyk Code - COBOL support now available in Snyk Preview</title>
          <link>https://updates.snyk.io/snyk-code-cobol-support-now-available-in-snyk-preview/</link>
          <description>&lt;p&gt;You can now scan COBOL codebases for security vulnerabilities using Snyk Code. This update helps large Organizations, particularly in retail and financial services, include legacy mainframe applications in their security programs and meet compliance or audit requirements.&lt;/p&gt;&lt;p&gt;Many Organizations manage significant COBOL codebases that previously lacked automated security scanning support. By adding COBOL support to Snyk Code, you can identify risks earlier in the development process and maintain a consistent security posture across your entire application portfolio.&lt;/p&gt;&lt;h3&gt;Supported features&lt;/h3&gt;&lt;p&gt;This release provides security coverage for standard COBOL, including CICS constructs.&lt;/p&gt;&lt;p&gt;Key features include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Support for .cbl, .ccp, .cob, and .cpy file extensions.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;15 security rules across cryptography, injection, secrets, and error handling.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Integration with the Snyk web UI for vulnerability management.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;How to get started&lt;/h3&gt;&lt;p&gt;You can access this feature through &lt;a href=&quot;https://docs.snyk.io/snyk-platform-administration/snyk-preview&quot;&gt;&lt;b&gt;Snyk Preview&lt;/b&gt;&lt;/a&gt;. &lt;/p&gt;</description>
          <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>ks4gXAMQo4IhsmGv5KwxP</guid>
          <category>New</category>
        </item>
        <item>
          <title>Snyk Code - Ruby Interfile GA</title>
          <link>https://updates.snyk.io/snyk-code-ruby-interfile-ga/</link>
          <description>&lt;p&gt;Snyk Code expands Ruby analysis with interfile data flow support&lt;/p&gt;&lt;p&gt;Starting April 7, 2026, Snyk Code includes interfile data flow analysis for all Ruby Projects. This update moves beyond single-file analysis to detect vulnerabilities that span multiple files, providing a more accurate assessment of your code.&lt;/p&gt;&lt;h3&gt;Improve Ruby on Rails security&lt;/h3&gt;&lt;p&gt;Ruby on Rails applications often distribute logic across models, views, and controllers. By analyzing data flows across the entire codebase rather than individual files, Snyk Code identifies complex vulnerabilities that were previously difficult to detect. We&amp;#39;ve also refreshed the Ruby on Rails ruleset to provide better coverage for modern development patterns.&lt;/p&gt;&lt;h3&gt;Key enhancements&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Interfile analysis:&lt;/b&gt;&lt;/p&gt;&lt;p&gt; You can now trace data flows across multiple files in all Ruby Projects scanned by Snyk Code.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Updated ruleset:&lt;/b&gt;&lt;/p&gt;&lt;p&gt; We&amp;#39;ve improved the Ruby on Rails rules to ensure more comprehensive vulnerability detection.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Zero configuration:&lt;/b&gt;&lt;/p&gt;&lt;p&gt; This feature is active by default for all customers on April 7, 2026, and requires no manual setup.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Support for security teams&lt;/h3&gt;&lt;p&gt;These improvements help security teams perform more effective risk assessments on large Ruby codebases. By closing the gap on interfile support, Snyk Code provides the same depth of analysis for Ruby as it does for other major languages.&lt;/p&gt;&lt;p&gt;Because analysis quality is enhanced, you may notice a change in your scan results, including new true positives and the removal of previous false positives. &lt;/p&gt;&lt;p&gt;For more information, you can review the current Ruby and rules documentation at &lt;a href=&quot;https://docs.snyk.io/&quot;&gt;https://docs.snyk.io&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Thu, 26 Mar 2026 09:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>6HrJY9j1aOfZP0cOzSyvZT</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Snyk API &amp; Web MCP Server</title>
          <link>https://updates.snyk.io/snyk-api-and-web-mcp-server/</link>
          <description>&lt;p&gt;Snyk API &amp;amp; Web MCP Server brings even more security to your IDE

You can use the Snyk API &amp;amp; Web MCP server to bring Snyk security capabilities directly into your AI-native development environment. By using the Model Context Protocol (MCP), you can use natural language to onboard targets, configure DAST authentication, scan targets, and triage vulnerabilities without leaving your IDE.&lt;/p&gt;</description>
          <pubDate>Tue, 24 Mar 2026 12:00:00 GMT</pubDate>
          <dc:creator>Ricardo Alves, Director, Product Management</dc:creator>
          <guid>7s3ZrESwZlit2SyeV80rxp</guid>
          <category>New</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1303.2</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1303-2/</link>
          <description>&lt;p&gt;We have released a new CLI hotfix (v1.1303.2) to address the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Security Fixes&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;We have implemented a fix for a vulnerability identified in our underlying gRPC library&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Snyk Open Source&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Optimized Privilege Evaluation: Resolved a bug where the CLI repeatedly checked user feature flags when scanning multiple Go projects, resulting in smoother performance.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Enhanced PackageURL Handling: Fixed an issue where Go projects using a replace directive with relative paths would encounter formatting errors.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Snyk Container&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Go Standard Library: This update introduces expanded support for the Go Standard Library within Snyk Container scans.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Snyk Evo (Agent Red Teaming)&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Attack Profiles: Users can now leverage the --profile flag to choose from pre-configured attack goals, including fast, security, and safety profiles.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Improved Terminology: We have updated our internal naming conventions for goals, strategies, and attacks to provide a more intuitive user experience.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Improved Onboarding: Interactive wizard to guide users through Agent Red Teaming configuration and setup.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Release notes can be found &lt;a href=&quot;https://github.com/snyk/cli/releases&quot;&gt;&lt;u&gt;here&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you have any questions, please don’t hesitate to reach out to the Snyk support team.&lt;/p&gt;</description>
          <pubDate>Mon, 23 Mar 2026 03:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>26xbTqQmHGAjNc2lVTtW6y</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>Snyk Code - March Update</title>
          <link>https://updates.snyk.io/snyk-code-march-update/</link>
          <description>&lt;p&gt;Starting March 30, 2026, we’ve updated Snyk Code to provide more accurate results and reduce developer friction. These improvements help you focus on exploitable production code by reducing false positives and automatically deprioritizing issues found in test environments.&lt;/p&gt;&lt;p&gt;By refining our detection logic across several languages, we&amp;#39;ve lowered noise and increased the catch rate for critical vulnerabilities.&lt;/p&gt;&lt;h3&gt;Improvements to scanning precision&lt;/h3&gt;&lt;p&gt;We&amp;#39;ve focused on three key areas to improve your triage experience:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Reduced noise: &lt;/b&gt;We&amp;#39;ve significantly lowered the number of false positives for .NET CSRF and JVM-based certificate validation.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Risk-based triage:&lt;/b&gt; JavaScript vulnerabilities located in test classes now appear as &lt;b&gt;Low&lt;/b&gt; severity. This change allows you to spend more time on production code rather than test mocks.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Higher confidence:&lt;/b&gt; We&amp;#39;ve increased the true positive catch rate for hardcoded passwords in PHP and CSRF vulnerabilities in Kotlin.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Language-specific updates&lt;/h3&gt;&lt;p&gt;You can see these improvements reflected in the following areas:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;.NET (C#): &lt;/b&gt;Enhanced CSRF detection with an 18% reduction in false positives.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;JavaScript:&lt;/b&gt; Automated detection of test classes to reclassify issues as &lt;b&gt;Low&lt;/b&gt; severity.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Java&lt;/b&gt;&lt;b&gt;/&lt;/b&gt;&lt;b&gt;Kotlin:&lt;/b&gt; Improved support for detecting disabled CSRF protection in Spring Apps and refined SQLi precision.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;JVM (Java, Groovy, Kotlin, Scala):&lt;/b&gt; Improved logic for &lt;b&gt;CWE-295&lt;/b&gt; (Improper Certificate Validation).&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;PHP:&lt;/b&gt; Expanded patterns for hardcoded password detection.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Important details to note&lt;/h3&gt;&lt;p&gt;All percentage improvements are based on Snyk’s curated open-source data set. As part of these updates, you may see a decrease in &lt;b&gt;High&lt;/b&gt; and &lt;b&gt;Medium&lt;/b&gt; severity counts for JavaScript as issues move to &lt;b&gt;Low&lt;/b&gt; based on their file location. These changes apply specifically to the languages and CWEs listed above, while other scan areas remain unchanged.&lt;/p&gt;</description>
          <pubDate>Thu, 12 Mar 2026 10:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>7h7BhxvmRDZLaGR8el0q1A</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Snyk Code - March Ruby Update</title>
          <link>https://updates.snyk.io/snyk-code-march-ruby-update/</link>
          <description>&lt;p&gt;Snyk Code updates for Ruby include Sinatra support and RSpec noise reduction&lt;/p&gt;&lt;p&gt;Starting March 23, 2026, we&amp;#39;ve updated Snyk Code to provide broader coverage and more precise results for Ruby developers. These improvements expand support to the Sinatra framework and general Ruby applications while helping you manage alert noise in test files.&lt;/p&gt;&lt;h3&gt;Expanding Ruby support beyond Rails&lt;/h3&gt;&lt;p&gt;You can now use Snyk Code to secure applications built with Sinatra or vanilla Ruby. We&amp;#39;ve added new sources, sinks, and sanitizers to our knowledge base to ensure your microservices and monoliths receive accurate security analysis regardless of the framework you choose.&lt;/p&gt;&lt;h3&gt;Reducing noise in RSpec test suites&lt;/h3&gt;&lt;p&gt;To prevent non-production vulnerabilities from cluttering your results, Snyk Code now automatically identifies RSpec files. The engine regrades security issues found in these files to &lt;b&gt;Low Severity&lt;/b&gt;. This change acknowledges the lower risk profile of test code and helps ensure your PR Checks remain focused on production-ready code.&lt;/p&gt;&lt;h3&gt;Higher precision for object-oriented code&lt;/h3&gt;&lt;p&gt;We&amp;#39;ve enhanced how Snyk Code tracks data flow through Ruby classes. The engine now better understands custom getters, setters, and direct field accesses. This improvement leads to more accurate detection and reduces both false positives and false negatives in complex codebases. Organizations making extensive use of custom fields can expect more reliable results that reflect how their data actually moves through the application.&lt;/p&gt;&lt;p&gt;To learn more, visit our &lt;a href=&quot;https://docs.snyk.io/&quot;&gt;Snyk User Documentation&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;To learn more, visit &lt;a href=&quot;https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-language-and-framework-support&quot;&gt;Snyk Code language and framework support&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Thu, 12 Mar 2026 00:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>3BYhTDAMwcAL4yb8R2iP9a</guid>
          <category>Improved</category>
        </item>
      </channel>
    </rss>