<?xml version="1.0" encoding="UTF-8"?>

    <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
      <channel>
        <title>snyk.io updates</title>
        <link>https://updates.snyk.io</link>
        <description>snyk.io updates</description>
        <language>en-us</language>
        <lastBuildDate>Sat, 03 Oct 2026 05:55:41 GMT</lastBuildDate>
        <atom:link href="https://updates.snyk.io/rss" rel="self" type="application/rss+xml" />
        
        <item>
          <title>ADS installer now available as a packaged binary</title>
          <link>https://updates.snyk.io/ads-installer-now-available-as-a-packaged-binary/</link>
          <description>&lt;p&gt;The ADS installer now ships as a signed macOS .pkg and Windows .msi, downloaded from the Settings page. The installer registers a scheduled job on the machine, so Agent Supply Chain Security scans run on their own schedule without needing MDM.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What&lt;/b&gt;
The ADS installer now ships as a signed macOS .pkg and Windows .msi, downloaded from the Settings page in Evo. &lt;/p&gt;&lt;p&gt;&lt;b&gt;Why&lt;/b&gt;
Deployment no longer means wrapping a downloaded file in your own script, you now get a standard signed installer for macOS or Windows. The installer now stays on the machine in a predictable location. Scan timing is no longer tied to your MDM policy.&lt;/p&gt;&lt;p&gt;&lt;b&gt;How&lt;/b&gt;
In Evo, open Settings, choose your products and select Save &amp;amp; Publish. Choose your operating system and architecture, select Download ADS Installer, install the package, then run the installer with your Tenant ID and push key. Your onboarding workflow, MDM policies, tenant and push key are all unchanged. Downloading the installer directly from the CDN remains available.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Things to know&lt;/b&gt;
Linux is unchanged. The command line install remains supported and is documented alongside the package flow. &lt;/p&gt;&lt;p&gt;For more information, see the documentation: https://docs.snyk.io/agent-security/evo-by-snyk/agentic-development-security-ads
&lt;/p&gt;</description>
          <pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate>
          <dc:creator>Nina Kanti, Senior Product Manager</dc:creator>
          <guid>1F0BSNetA4HG44FbaHg2R4</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1307.4</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1307-4/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1307.4&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1307.4&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;New experimental &lt;code&gt;snyk studio&lt;/code&gt; command that sets up Snyk Studio in supported AI coding tools (Cursor, Claude Code, Codex, Copilot, Gemini, Kiro, and Windsurf), so the code they generate gets scanned in the background as it&amp;#39;s written. This direct integration replaces the need for separate setup scripts (https://github.com/snyk/studio-recipes). Run &lt;code&gt;snyk studio install --experimental&lt;/code&gt; to get started. &lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;New &lt;code&gt;snyk fix --agentic&lt;/code&gt; filtering flags: &lt;code&gt;--severity-filter&lt;/code&gt; to fix only the severities you choose, &lt;code&gt;--breakability-filter&lt;/code&gt; to fix only Open Source upgrades with the breakability you choose, and &lt;code&gt;--exclude-ids&lt;/code&gt; to fix everything except the issue IDs you list.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk fix --agentic&lt;/code&gt; now keeps a failed fix&amp;#39;s changes by default so you can review them, rather than reverting automatically. Pass &lt;code&gt;--enable-revert&lt;/code&gt; to restore the automatic rollback behavior.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed an issue where the &lt;code&gt;--iac&lt;/code&gt;, &lt;code&gt;--docker&lt;/code&gt;, &lt;code&gt;--container&lt;/code&gt;, and &lt;code&gt;--code&lt;/code&gt; flags on &lt;code&gt;snyk test&lt;/code&gt; could be silently dropped for organizations on the unified test API, causing scans to fall through to an open-source test instead (which could fail with &amp;quot;No supported files found&amp;quot; or scan the wrong target). These flags now route to the correct scan again.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Wed, 23 Sep 2026 16:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>6Rzn1YwTNVO3V9Q3iUtxgf</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>A change to the Snyk Code Priority Score</title>
          <link>https://updates.snyk.io/a-change-to-the-snyk-code-priority-score/</link>
          <description>&lt;p&gt;Snyk Code priority scores dropped by up to 200 points on September 1, 2026, for findings whose rule had a fix example.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What changed&lt;/b&gt;&lt;/p&gt;&lt;p&gt;A finding used to earn 200 of the 1,000 available priority score points when Snyk held a fix example for its rule. The &lt;a href=&quot;https://updates.snyk.io/snyk-code-august-update/&quot;&gt;&lt;u&gt;August 17, 2026 release&lt;/u&gt;&lt;/a&gt; retired fix examples, and the scoring factor went with them. The removal became live on September 1, 2026.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Why&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Fix-example availability describes Snyk&amp;#39;s content coverage. It says nothing about the risk in your code. Two findings of the same severity could sit 200 points apart because one rule happened to have an example behind it. Priority score should rank findings by how urgently they need fixing, so we removed the factor.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What you saw&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Snyk Code findings reordered when the factor came out. Every remaining scoring factor works as it did before, including severity, which still contributes the largest single share at up to 500 points. &lt;b&gt;No finding was added, removed or re-rated.&lt;/b&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;We should have told you&lt;/b&gt;&lt;/p&gt;&lt;p&gt;The August 17 release notes said no action was required. That was wrong, and we apologize. We have added a check so that any future change to priority score appears in the release notes. The priority score documentation now lists the current factors.&lt;/p&gt;&lt;p&gt;Learn more in the &lt;a href=&quot;https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/breakdown-of-code-analysis#priority-score-factors&quot;&gt;&lt;u&gt;Snyk Code priority score documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Wed, 23 Sep 2026 15:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>5M8Kb9O979lMvFVZhObx2G</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Snyk for Jira moves from Atlassian Connect to Forge</title>
          <link>https://updates.snyk.io/snyk-for-jira-moves-from-atlassian-connect-to-forge/</link>
          <description>&lt;p&gt;Atlassian ends support for &lt;a href=&quot;https://www.atlassian.com/blog/development/announcing-connect-end-of-support-timeline-and-next-steps&quot;&gt;Atlassian Connect in December 2026&lt;/a&gt;. Snyk for Jira has been rebuilt on Forge, Atlassian&amp;#39;s current cloud app platform, with all of the same functionality.&lt;/p&gt;&lt;p&gt;No action is required. New installations use the Forge version from September 30, 2026, and existing installations will be migrated during October. Permissions, configuration, ticket creation, and existing Jira issues all carry over unchanged.&lt;/p&gt;&lt;p&gt;For more information, see &lt;a href=&quot;https://docs.snyk.io/developer-tools/integrations/jira-and-slack-integrations/snyk-security-in-jira-cloud-integration&quot;&gt;&lt;u&gt;Snyk for Jira documentation&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;
&lt;/p&gt;</description>
          <pubDate>Wed, 23 Sep 2026 03:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>75EhBunI8NXbvBE3ceKhDS</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Evo MCP Server now available </title>
          <link>https://updates.snyk.io/evo-mcp-server-now-available/</link>
          <description>&lt;p&gt;You can connect any MCP client, such as Claude, Codex or Cursor, to Evo and ask about your AI estate from the agent you already work in. &lt;/p&gt;&lt;p&gt;What&amp;#39;s new. You can now:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Ask what AI assets Evo has discovered across your code, your developer machines, and your pentest targets&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;See how those assets connect, for example which MCP servers an agent uses or which findings came from a target&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Read your policies and the violations open against them&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Create and update policies without leaving your agent&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;To get started, check out our &lt;a href=&quot;https://docs.snyk.io/agent-security/evo-by-snyk/platform-surfaces&quot;&gt;documentation&lt;/a&gt;&lt;/p&gt;</description>
          <pubDate>Tue, 22 Sep 2026 18:00:00 GMT</pubDate>
          <dc:creator>Nina Kanti, Senior Product Manager</dc:creator>
          <guid>26x3KhY0338R2aMyp7vmhN</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1307.3</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1307-3/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1307.3&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1307.3&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk test &lt;/code&gt;now reports an unreadable &lt;code&gt;.snyk&lt;/code&gt; policy file as &lt;code&gt;SNYK-POLICY-0002&lt;/code&gt; with a message identifying the problem, instead of an unspecified error.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk test --all-projects&lt;/code&gt; now resolves each project&amp;#39;s &lt;code&gt;.snyk&lt;/code&gt; policy from that project&amp;#39;s own directory, instead of applying the scan root&amp;#39;s policy to every project.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk test --scan-all-unmanaged&lt;/code&gt; no longer fails with exit code 2 when scanning a directory of JARs with no manifest file.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;CVE-2026-63376&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-77465&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://security.snyk.io/vuln/SNYK-JS-ADMZIP-19846655&quot;&gt;SNYK-JS-ADMZIP-19846655&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Fri, 18 Sep 2026 08:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>4aug2hKe0pkNBYQo1683iF</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>Container: Go standard library vulnerability reporting</title>
          <link>https://updates.snyk.io/container-go-standard-library-vulnerability-reporting/</link>
          <description>&lt;p&gt;Snyk Container will begin reporting vulnerabilities from the Go standard library for all customers. Scans of container images built from Go binaries identify the standard library version the binary was compiled with and report known vulnerabilities against it.&lt;/p&gt;&lt;p&gt;Affected images gain a new stdlib dependency in the dependency graph, versioned to the Go release used for the build, for example stdlib@1.25.10. Detection works for standard, stripped, and CGo builds.&lt;/p&gt;&lt;p&gt;No configuration is required, and reporting is enabled automatically for all organizations. Standard library reporting in the Snyk CLI requires v1.1303.2 or later.&lt;/p&gt;&lt;p&gt;This change is scheduled to take effect on October 7, 2026.&lt;/p&gt;</description>
          <pubDate>Wed, 16 Sep 2026 04:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>4sz2PIvMjPLtlpnxldceve</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Custom CA Certificate Support</title>
          <link>https://updates.snyk.io/custom-ca-certificate-support/</link>
          <description>&lt;p&gt;Snyk API &amp;amp; Web now lets you upload your organization&amp;#39;s internal Certificate Authority (CA), so the certificates it issues are trusted the same way as publicly issued certificates.&lt;/p&gt;&lt;h2&gt;What&amp;#39;s new&lt;/h2&gt;&lt;p&gt;Many enterprises operate their own internal CA to issue certificates for both internal tools and internet-facing applications. Although these certificates aren&amp;#39;t signed by a public CA, they should still be included in scans to prevent false positives.&lt;/p&gt;&lt;h2&gt;What we&amp;#39;re delivering&lt;/h2&gt;&lt;p&gt;A method for uploading your Root CA. Each scan of every target then verifies certificates against your CA and the public trust store.&lt;/p&gt;&lt;p&gt;This increases scan accuracy, reduces the overhead of documenting risk acceptance for each affected target, and boosts the overall precision of each scan based on your specific needs and requirements.&lt;/p&gt;</description>
          <pubDate>Tue, 15 Sep 2026 23:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>5HapY6kCK7k4djvC3fHZY9</guid>
          <category>New</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1307.2</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1307-2/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1307.2&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1307.2&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Removed an unused experimental feature.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities: &lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;CVE-2026-84445&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Wed, 09 Sep 2026 15:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>3f9GSrGpZMJvlQcbwVJc78</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1307.1</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1307-1/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1307.1&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1307.1&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk test&lt;/code&gt; again reports &lt;code&gt;SNYK-CLI-0008&lt;/code&gt; and exits with code 3 when a repository contains no supported manifest files, instead of a generic &lt;code&gt;SNYK-CLI-0000&lt;/code&gt; with exit code 2. &lt;code&gt;snyk test --json&lt;/code&gt; writes the error document to stdout as expected.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Restored the &lt;code&gt;moduleName&lt;/code&gt;, &lt;code&gt;insights.triageAdvice&lt;/code&gt;, and &lt;code&gt;functions_new&lt;/code&gt; fields in &lt;code&gt;snyk test --json&lt;/code&gt; output, so tooling that consumes those fields works as before.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;.snyk&lt;/code&gt; policy files are now handled correctly in the unified test flow. This covers empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that could previously cause incorrect results or failures.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Commands that complete with findings (exit code 1) no longer produce duplicate or corrupt JSON output when an unrelated network error occurs during the run, improving reliability for automated pipelines that parse CLI output.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;The debug-log scrubber now masks secrets consistently and no longer corrupts the surrounding JSON structure, making debug logs safer to share and easier to parse.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Container scans now surface source repository information for locally built images using BuildKit metadata.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;CVE-2022-25883&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-84304&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-84375&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://security.snyk.io/vuln/SNYK-GOLANG-GOLANGORGXCRYPTOSSH-19504090&quot;&gt;SNYK-GOLANG-GOLANGORGXCRYPTOSSH-19504090&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Mon, 07 Sep 2026 15:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>1zO7tfLxCTd2HqCLa6sX65</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>Snyk Projects now stay in sync with your repository content</title>
          <link>https://updates.snyk.io/repo-content-sync/</link>
          <description>&lt;p&gt;&lt;u&gt;&lt;b&gt;The &amp;quot;What&amp;quot;&lt;/b&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;Repo Content Sync keeps your Snyk Projects aligned with what your repositories actually contain. When a change is merged to a branch Snyk monitors, Snyk creates and begins monitoring Projects for newly added manifest, Dockerfile, and configuration files, and deactivates the Projects whose files were removed. A file that is moved or renamed is picked up at its new path, and the Project at the old path is deactivated.

Until now, keeping Snyk in step with a repository was a manual step: someone re-imported the repository, or a newly added dependency file simply went unscanned. Repo Content Sync makes repository content itself the trigger, so your Project list reflects the code as it is today rather than as it was at import.

Sync covers Code, open source, secrets, infrastructure as code, and container (Dockerfile) Projects, and it works on custom branches as well as default branches.&lt;/p&gt;&lt;p&gt;Repo Content Sync will be rolled out gradually over the next several weeks.&lt;/p&gt;</description>
          <pubDate>Mon, 31 Aug 2026 16:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>6pjhT1Pb6nZxO3zVxjsWyd</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1307.0</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1307-0/</link>
          <description>&lt;p&gt;We are pleased to announce the latest stable Snyk CLI release, v1.1307.0.&lt;/p&gt;&lt;p&gt;We are introducing the following key improvements in this version. To learn more about bug fixes and additional enhancements beyond what is highlighted below, please reference the full release notes.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Secrets&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk secrets test&lt;/code&gt; now supports exclusions — add files or paths to the &lt;code&gt;exclude&lt;/code&gt; section of your &lt;code&gt;.snyk&lt;/code&gt; file to skip them during secrets scanning.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Container&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Container scans now surface image provenance attestations by default, so signed-image provenance metadata appears in results without any extra flag.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;.NET/NuGet&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk test&lt;/code&gt; can now analyze already-restored .NET/NuGet projects fully offline and no longer requires .NET 6 to be installed.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;The full Snyk MCP profile now includes Snyk Secrets.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Code &amp;amp; Secrets&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;SARIF suppressions now include &lt;code&gt;reviewedOn&lt;/code&gt; and &lt;code&gt;reviewedBy&lt;/code&gt; metadata.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;AI BOM&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;snyk aibom test --severity-threshold&lt;/code&gt; now filters the displayed and JSON results by severity, not only the exit code.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Agent-optimized CLI&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;New experimental &lt;code&gt;snyk agent&lt;/code&gt; command space — a scanning surface built for AI coding agents, with token-optimized output and ergonomics. &lt;code&gt;snyk agent test&lt;/code&gt; runs Snyk Open Source, Code, and Secrets together.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Additional Reliability and Performance Improvements&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Adds support for scanning pnpm v11 &lt;code&gt;pnpm-lock.yaml&lt;/code&gt; lockfiles.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixes a crash when scanning dependencies of Gradle 7.4–8.2 projects.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixes a bug where arguments after &lt;code&gt;--&lt;/code&gt; (for example &lt;code&gt;snyk test . -- -s settings.xml&lt;/code&gt;) were treated as scan targets, which could silently drop the Risk Score.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixes scanning of projects using Hex versions newer than 1.19.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Excludes the &lt;code&gt;.git&lt;/code&gt; folder from file discovery, preventing intermittent scan failures caused by changes to &lt;code&gt;.git&lt;/code&gt; contents during a scan&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Prevents a possible connection leak when the Snyk API returns an error response.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Updates dependencies to fix vulnerabilities.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Release notes can be found &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1307.0&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these new features and improvements.&lt;/p&gt;</description>
          <pubDate>Wed, 26 Aug 2026 15:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>5yLypBqdHTMSVzz6y6jWIA</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Organization-scoped access in Evo</title>
          <link>https://updates.snyk.io/organization-scoped-access-in-evo/</link>
          <description>&lt;p&gt;Starting August 18, 2026, a user&amp;#39;s Evo data is limited to the Snyk Organizations they can read.&lt;/p&gt;&lt;p&gt;Until now, everyone with access to Evo saw every repository, asset, and issue in the Tenant. Evo now
reuses your existing Snyk Organization hierarchy, so there is nothing new to model and no migration to
run. Nobody loses access until an administrator changes their role.&lt;/p&gt;&lt;h3&gt;What&amp;#39;s new:&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Tenant Viewer now grants read access to the assets and issues in the Organizations the user belongs to, and to nothing outside them&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Tenant Member grants no Evo access, letting administrators withhold Evo without removing Snyk platform access&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Full-Tenant access continues for Tenant Admin and for the two roles ending in &amp;quot;with Evo access&amp;quot;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Organization names appear alongside repositories, distinguishing the same repository imported into more than one Organization&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h3&gt;Note for administrators:&lt;/h3&gt;&lt;p&gt;Existing users keep their access, and Tenant Viewers gain scoped read access for the first time. New
users join as Tenant Member, which carries no Evo access, so each one needs a role change. Scoped
users are read only, and assets without an Organization stay hidden, which today means all Agent
Supply Chain Security and Continuous Offensive Security data.&lt;/p&gt;&lt;p&gt;Documentation: &lt;a href=&quot;https://docs.snyk.io/agent-security/evo-by-snyk/access-and-authentication&quot;&gt;Access and authentication&lt;/a&gt;&lt;/p&gt;</description>
          <pubDate>Tue, 25 Aug 2026 18:33:00 GMT</pubDate>
          <dc:creator>Ranko Cupovic, Principal Product Manager</dc:creator>
          <guid>2YSuQU9Tmmj2lKwVFxGuZ3</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Snyk Code September Update</title>
          <link>https://updates.snyk.io/snyk-code-september-update/</link>
          <description>&lt;p&gt;This update is available on &lt;b&gt;September 14, 2026&lt;/b&gt;. It improves coverage and precision across Snyk Code: template files are analyzed, Java framework and library support is extended, detection gaps are closed in six languages, and .gitignore no longer hides committed files from analysis.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Template files&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Snyk Code analyzes template files and follows data from your application code into the template. Cross-site scripting that only becomes exploitable where the template renders its output is now reported, with the data flow shown from the application through to the template.&lt;/p&gt;&lt;p&gt;Supported engines: Jinja2, Razor, FreeMarker, EJS, Handlebars, Pug, Thymeleaf, Twig, Mustache and Velocity.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Java&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Apache CXF&lt;/b&gt; — the web services framework, including its HTTP transport.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;OkHttp&lt;/b&gt; — the HTTP client.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Spring Security OAuth2 Client&lt;/b&gt; — OAuth2 and OpenID Connect authentication.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Google OAuth Client&lt;/b&gt; and &lt;b&gt;Google API Client&lt;/b&gt; — Google authentication and API access.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;MSAL4J&lt;/b&gt; — Microsoft identity platform authentication.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Apache Commons Collections&lt;/b&gt; — collection utilities.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Flyway&lt;/b&gt; — database migrations.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;JAXB&lt;/b&gt; — XML binding.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;SAP Commerce (Hybris)&lt;/b&gt; — FlexibleSearch queries, with parameter binding recognised as safe.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Coverage for these libraries is added or improved, resulting in improved data flow analysis.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Python&lt;/b&gt;&lt;/p&gt;&lt;p&gt;LangChain LiteLLM is recognised as a source of untrusted data.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Java 25&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Java 25 source is analyzed.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Rule coverage improvements&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Detection coverage is extended for &lt;b&gt;Java, Kotlin, C#, Go, JavaScript and PHP&lt;/b&gt; — additional sources, sinks and unsafe API patterns, in particular for cryptography.&lt;/p&gt;&lt;p&gt;Expect additional true positives and fewer false positives.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Files matched by .gitignore&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Committed files matched by a .gitignore rule are analyzed.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Secrets committed and later matched by a .gitignore rule are now detected. Git ignores only untracked files, so this brings Snyk Code and Snyk Secrets in line with Git.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;These are pre-existing issues in code you already committed.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;The change applies across all interfaces and cannot be disabled.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Required for CLI scans.&lt;/b&gt; Upgrade to Snyk CLI 1.1307.0 or later, available from 26 August. Earlier versions keep the previous behavior, so CLI results will differ from your SCM and web results. SCM imports and scans need no action.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What is unchanged&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Untracked files matched by .gitignore remain excluded from analysis.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;.snyk exclude patterns behave as before, and remain the way to exclude a path deliberately.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Severity levels and rule identifiers do not change.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;</description>
          <pubDate>Fri, 21 Aug 2026 08:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>5L0xa8XdaOpYR1kjxlt1OD</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>New model risk scoring for AI models in Evo</title>
          <link>https://updates.snyk.io/model-risk-score-evo-ga/</link>
          <description>&lt;p&gt;Starting August 17, 2026, Evo by Snyk uses a rebuilt model risk score to evaluate the AI models discovered in your organization.&lt;/p&gt;&lt;p&gt;The previous Risk Index is replaced by a single score from 0–1,000 that combines attack success rate with the potential impact of a successful attack, tested against categories including prompt injection, data exfiltration, and insecure code generation. The result is a score that reflects both how easily a model can be compromised and how much damage that compromise could cause — not just whether an attack succeeded.&lt;/p&gt;&lt;p&gt;What&amp;#39;s new:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Impact-weighted scoring:&lt;/b&gt; Risk scores now factor in the real-world consequence of an attack succeeding, not only its likelihood.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Four severity bands:&lt;/b&gt; Scores map to low (0–249), medium (250–499), high (500–749), and critical (750–1,000), so you can triage at a glance.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Broader attack coverage:&lt;/b&gt; Testing spans a wider range of direct and indirect attack categories against each discovered model.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Framework-mapped:&lt;/b&gt; Findings map to OWASP LLM Top 10, OWASP Agentic Security, MITRE ATLAS, and NIST AI 600-1/100-2e2025, so you can connect model risk to the compliance frameworks you already report against.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Policy-ready from day one:&lt;/b&gt; Evo applies default policies across common attack categories automatically, and you can create custom policies scoped to specific attack categories or goals to match your organization&amp;#39;s risk tolerance.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;If you have policies built on the old Risk Index:&lt;/b&gt; those policies remain visible but no longer evaluate under the new scoring. Review and recreate any Risk Index-based policies against the new model risk score to keep enforcement active.&lt;/p&gt;&lt;p&gt;Read more in the Risk intelligence &lt;a href=&quot;http://docs.snyk.io/agent-security/evo-by-snyk/ai-spm/risk-intelligence&quot;&gt;documentation&lt;/a&gt;.&lt;/p&gt;</description>
          <pubDate>Wed, 19 Aug 2026 15:00:00 GMT</pubDate>
          <dc:creator>Ranko Cupovic, Principal Product Manager</dc:creator>
          <guid>1W3f0okRBUn45Q63RKJFbX</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Snyk Assist— AI-powered support and guidance, built into Snyk</title>
          <link>https://updates.snyk.io/snyk-assist-in-ui/</link>
          <description>&lt;p&gt;&lt;u&gt;&lt;b&gt;The &amp;quot;What&amp;quot;&lt;/b&gt;&lt;/u&gt;&lt;/p&gt;&lt;p&gt;Snyk is introducing Snyk Assist — an AI-powered support and guidance assistant available directly inside the Snyk UI.&lt;/p&gt;&lt;p&gt;Snyk Assist answers product, setup, and troubleshooting questions in plain language, grounded in Snyk&amp;#39;s own documentation, release notes, and support knowledge articles. It can also retrieve read-only information about your current organization and group, and open a support case without you leaving the conversation.&lt;/p&gt;&lt;p&gt;Assist is available from the top right of the screen on every page, and is always accessible.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Ask questions in plain language:&lt;/b&gt; product concepts, account setup, integrations, and day-to-day administration — &amp;quot;How do I set up SSO?&amp;quot;, &amp;quot;What permissions does Snyk need for my GitHub org?&amp;quot;, &amp;quot;How do I configure ignore rules and approvals?&amp;quot;. Answers are grounded in Snyk documentation and tailored to your role, plan tier, and licensed products.
&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Self-serve troubleshooting:&lt;/b&gt; conversational diagnostics drawn from Snyk&amp;#39;s support and knowledge articles, so common problems can be resolved without waiting on a ticket.
&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Information about your account:&lt;/b&gt; issue summaries by severity, issue triage and single-issue detail, projects and import targets, collections and container images, scan settings, integrations and their connectivity status, members and their roles, and a project&amp;#39;s current ignore rules — for your current organization and group, retrieved with your own permissions.
&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Support without leaving the conversation:&lt;/b&gt; Assist can suggest and create a support case and return the case ID and link. When it detects a capability Snyk does not support today, it can capture that as a feature request.
&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Vulnerability lookups:&lt;/b&gt; look up known vulnerabilities for a package, or a specific package version, against the Snyk Vulnerability Database.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Snyk Assist requires the new Snyk UI. It is available only to users who have the new navigation experience enabled. If you are still on the classic navigation, switch via the user account menu to use Assist.&lt;/p&gt;&lt;p&gt;Snyk Assist is available to Team, Ignite and Enterprise plans.&lt;/p&gt;</description>
          <pubDate>Tue, 18 Aug 2026 04:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>3mbLBZYECQNYAQ7S0e3J8B</guid>
          <category>Early access</category>
        </item>
        <item>
          <title>Unified Navigation, Navigation search and Dark Mode — New Snyk UI Rollout!</title>
          <link>https://updates.snyk.io/new-snyk-ui/</link>
          <description>&lt;p&gt;Snyk is rolling out a redesigned navigation experience! &lt;/p&gt;&lt;p&gt;The classic sidebar — which listed every page across Tenant, Group, and Organization scopes at once — is replaced by a single breadcrumb bar at the top that lets users switch scope in one click via per-level drop-downs. &lt;/p&gt;&lt;p&gt;The left sidebar is condensed to core areas only (Analytics, Inventory, Projects, Issues, Policies, Settings), with all settings-related pages consolidated into one context-aware Settings hub. &lt;/p&gt;&lt;p&gt;The update also adds a &amp;quot;Dark Mode&amp;quot; option (System/Light/Dark) under the user account menu. and a UI/Cmd/Ctrl+K command search to jump directly to any page or setting for easy orientation.&lt;/p&gt;</description>
          <pubDate>Mon, 17 Aug 2026 05:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>2QFcOMNSeyWNweDoVaaMbN</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1306.4</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1306-4/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1306.4&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1306.4&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Clearer error messages when the CLI cannot reach a configured proxy. Failures now report the proxy URL the CLI attempted to use, with credentials redacted, along with the specific error code &lt;code&gt;SNYK-CLI-0028&lt;/code&gt;, making proxy misconfiguration quicker to diagnose in CI and behind corporate networks.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;An updated embedded runtime, moving Node.js from 22.22.2 to 22.23.2 and OpenSSL from 3.5.5 to 3.5.7, which brings in fixes for six high-severity CVEs plus additional OpenSSL security fixes.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://security.snyk.io/vuln/SNYK-JS-JSYAML-18593780&quot;&gt;SNYK-JS-JSYAML-18593780&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-45447&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-48618&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-48933&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-56846&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-56848&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-58043&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Thu, 13 Aug 2026 15:00:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>3Tx7MBhC6zhBzpcu9YTrcG</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1306.3</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1306-3/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1306.3&lt;/p&gt;&lt;p&gt;This release contains security fixes. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1306.3&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Updates bundled dependencies to remediate known vulnerabilities, keeping the CLI current for teams with supply chain policies on the tools running in their pipelines.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://security.snyk.io/vuln/SNYK-JS-SHESCAPE-18319522&quot;&gt;SNYK-JS-SHESCAPE-18319522&lt;/a&gt; (CVE-2026-14257)&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;CVE-2026-69152&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Thu, 06 Aug 2026 12:40:00 GMT</pubDate>
          <dc:creator>Matt Dolan, Senior Product Manager</dc:creator>
          <guid>xrZtlOwibL3pLZ6KAkHK2</guid>
          <category>Fix</category>
        </item>
        <item>
          <title>NTLM Authentication in Snyk API &amp; Web</title>
          <link>https://updates.snyk.io/ntlm-authentication-in-snyk-api-and-web/</link>
          <description>&lt;p&gt;Snyk API &amp;amp; Web now supports NTLM v2 authentication for Web targets. Security teams can configure NTLM credentials (username, password, domain, workstation) directly in the target settings, enabling authenticated scans of Windows-authenticated applications without requiring separate tools.&lt;/p&gt;</description>
          <pubDate>Wed, 05 Aug 2026 14:30:00 GMT</pubDate>
          <dc:creator>Ana Pascoal, Product Manager</dc:creator>
          <guid>453DfTMuj3QAYyv0LprU3r</guid>
          <category>New</category>
        </item>
        <item>
          <title>Snyk secrets scanner reaches general availability</title>
          <link>https://updates.snyk.io/snyk-secrets-scanner-reaches-ga/</link>
          <description>&lt;p&gt;Starting August 4, 2026, Snyk secrets scanner is generally available to help secure your entire SDLC against credential leaks.&lt;/p&gt;&lt;p&gt;Stolen credentials remain a leading initial access vector in security breaches, and the rise of AI-generated code increases the risk of exposing sensitive data. You can now use Snyk secrets scanner to detect hardcoded credentials, API keys, and tokens across your repositories and prevent them from reaching commits or being leaked.&lt;/p&gt;&lt;p&gt;Key capabilities include:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Machine learning driven detection and prevention across your development surfaces.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Secrets detection for both human-written and AI-generated code.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Governance and finding management directly within the Snyk web UI.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;For more information, please read the &lt;a href=&quot;https://snyk.io/blog/snyk-secrets/&quot;&gt;blog&lt;/a&gt; and &lt;a href=&quot;https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-secrets&quot;&gt;Snyk Secrets documentation&lt;/a&gt;&lt;/p&gt;</description>
          <pubDate>Wed, 05 Aug 2026 13:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>70bXuyXT4d4CBxMAih8TFG</guid>
          <category>New</category>
        </item>
        <item>
          <title>Governed ignores with Ignore Approval Workflow (IAW)</title>
          <link>https://updates.snyk.io/code-ignore-approval-workflow/</link>
          <description>&lt;p&gt;Until now, a developer could suppress a Snyk Code finding on their own — directly in the Web UI or IDE — with no review step. &lt;/p&gt;&lt;p&gt;Suppression happened silently and unilaterally, leaving security teams without a gate on what got ignored.&lt;/p&gt;</description>
          <pubDate>Mon, 03 Aug 2026 14:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>1PjjIFyxLpkEtmKl4r8LTh</guid>
          <category>General availability</category>
        </item>
        <item>
          <title>COBOL support for Snyk Code</title>
          <link>https://updates.snyk.io/cobol-support-for-snyk-code/</link>
          <description>&lt;p&gt;COBOL support becomes generally available on August 17, 2026. Snyk Code brings SAST to your mainframe applications, scanning fixed-format COBOL across the integrations you already use, so mainframe code receives the same real-time, in-workflow security coverage as the rest of your stack. Detection is tuned with feedback from design-partner environments across large finance and mainframe estates.&lt;/p&gt;&lt;p&gt;&lt;b&gt;What you can do&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Scan COBOL applications for security issues alongside your other languages, with no separate workflow.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Catch real, actionable findings, with COBOL engagement in line with mainline languages.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Bring mainframe AppSec into the CLI, IDE, SCM, and PR-check integrations your teams already use.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Scope change at general availability&lt;/b&gt;&lt;/p&gt;&lt;p&gt;At general availability, the COBOL preview flag is removed and COBOL scanning runs automatically across all repositories. You may see new findings in repositories that were not scanned during the preview.&lt;/p&gt;&lt;p&gt;&lt;b&gt;For design-partner customers&lt;/b&gt;&lt;/p&gt;&lt;p&gt;Thank you for shaping COBOL support during early access.&lt;/p&gt;</description>
          <pubDate>Fri, 31 Jul 2026 08:00:00 GMT</pubDate>
          <dc:creator>Sebastian Roth, Senior Product Manager</dc:creator>
          <guid>2gMiz71UAdnDspSB5c4OM6</guid>
          <category>New</category>
        </item>
        <item>
          <title>Snyk Code August Update</title>
          <link>https://updates.snyk.io/snyk-code-august-update/</link>
          <description>&lt;p&gt;This update is available on August 17, 2026. It broadens language and framework coverage, adds serverless and LangChain support for Python, and cuts false positives in C++ and C#.&lt;/p&gt;&lt;p&gt;&lt;b&gt;Python&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;LangChain support&lt;/b&gt; — Snyk Code covers applications that use LangChain, flagging unsafe handling of data flowing through the framework.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Serverless support&lt;/b&gt; — Snyk Code covers Python applications running on AWS Lambda.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;New detection&lt;/b&gt; — weak-hash detection and detection of debug features left enabled.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Java&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;Spring Data coverage&lt;/b&gt; — data read through Spring Data repositories is tracked as a taint source, so injection, SSRF, path-traversal, and XSS findings reflect data flowing from the Spring Data layer.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;b&gt;New framework recognition&lt;/b&gt; — vert.x, Jolokia, and Spring Cloud Config Client.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Reduced noise&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Fewer false positives in C++ DoubleFree and C# Code Injection.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;b&gt;Change to fix examples&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Fix examples no longer appear in &lt;b&gt;Fix analysis&lt;/b&gt; in the Snyk Web UI, and no longer appear in SARIF output. The issue details, the data flow, and the CWE reference are unchanged.&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;To remediate a Snyk Code finding, use Snyk Agent Fix. It generates a fix for that specific finding in your own code and verifies the fix by rescanning. See &lt;a href=&quot;https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-code/manage-code-vulnerabilities/fix-code-vulnerabilities-automatically&quot;&gt;&lt;u&gt;Fix code vulnerabilities automatically&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Overall, this release increases true-positive coverage and reduces false positives.&lt;/p&gt;</description>
          <pubDate>Thu, 30 Jul 2026 23:00:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>7laX7xiLQxy7PPEbLNmJlm</guid>
          <category>Improved</category>
        </item>
        <item>
          <title>Announcing Snyk CLI v1.1306.2</title>
          <link>https://updates.snyk.io/announcing-snyk-cli-v1-1306-2/</link>
          <description>&lt;p&gt;We are pleased to announce Snyk CLI release, v1.1306.2&lt;/p&gt;&lt;p&gt;This release contains fixes and minor improvements. To learn more beyond what is highlighted below, please reference the &lt;a href=&quot;https://github.com/snyk/cli/releases/tag/v1.1306.2&quot;&gt;full release notes&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;b&gt;This update includes the following:&lt;/b&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;Improved authentication handling in the Snyk Language Server, which powers Snyk&amp;#39;s IDE integrations&lt;/p&gt;&lt;/li&gt;&lt;li&gt;&lt;p&gt;Fixed vulnerabilities:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;a href=&quot;https://security.snyk.io/vuln/SNYK-GOLANG-GOOGLEGOLANGORGGRPCINTERNALXDSRBAC-18172577&quot;&gt;SNYK-GOLANG-GOOGLEGOLANGORGGRPCINTERNALXDSRBAC-18172577&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If you have any questions, feel free to reach out to the Snyk support team. We encourage everyone to upgrade to the latest version to take advantage of these improvements.&lt;/p&gt;</description>
          <pubDate>Mon, 27 Jul 2026 15:27:00 GMT</pubDate>
          <dc:creator>undefined, undefined</dc:creator>
          <guid>3Oct7DGh88kF7aw4n62Ka8</guid>
          <category>Fix</category>
        </item>
      </channel>
    </rss>