Repository navigation
Releases: snyk/cli
Release list
v1.1307.4
1.1307.4 (2026-09-23)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
- studio: New experimental
snyk studiocommand that sets up Snyk Studio in your AI coding tools (Cursor, Claude Code, Codex, Copilot, Gemini, Kiro, Windsurf), so the code they generate gets scanned in the background as it's written. Runsnyk studio install --experimentalto get started. (49653c8) - fix: New
snyk fix --agenticflags to narrow down what gets fixed:--severity-filterfixes only the listed severities,--breakability-filterfixes only Open Source upgrades with the listed breakability, and--exclude-idsfixes everything except the listed issue IDs. (35298ae) - fix:
snyk fix --agenticnow keeps a failed fix's changes by default so you can review them, and reports the fix as failed. Pass--enable-revertto roll the changes back automatically instead. (35298ae)
Bug Fixes
- test:
--iac,--docker,--containerand--codeno longer get silently dropped for orgs on the unified test API — each now runs the correct scan again instead of an open-source test (which could fail with "No supported files found" or scan the wrong target). (87568ab)
v1.1307.3
1.1307.3 (2026-09-17)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
- test: Reports an unreadable
.snykpolicy file as SNYK-POLICY-0002 with a message identifying the problem, instead of an unspecified error. (4ada635) - test:
--all-projectsnow resolves each project's.snykpolicy from that project's own directory, instead of applying the scan root's policy to every project. (f17550f) - test:
--scan-all-unmanagedno longer fails with exit code 2 when scanning a directory of JARs with no manifest file. (4f8643b) - deps: Updates dependencies to fix vulnerabilities:
- CVE-2026-63376, CVE-2026-77465 (b93aa46)
- SNYK-JS-ADMZIP-19846655 (97689ff)
v1.1307.2
1.1307.2 (2026-09-09)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
- security: Removed an unused experimental feature. (ad487e9)
- deps: Updates dependencies to fix vulnerabilities:
v1.1307.1
1.1307.1 (2026-09-07)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
- test:
snyk teston a repository with no supported manifest files again reportsSNYK-CLI-0008and exits 3, instead of a genericSNYK-CLI-0000with exit 2.snyk test --jsonwrites the error document to stdout as expected. (50cad38) - test: Restores
moduleName,insights.triageAdvice, andfunctions_newfields insnyk test --jsonoutput. (4ec3d18) - test:
.snykpolicy files are now handled correctly in the unified test flow -- empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that previously caused incorrect results or failures. (a22a563) - general: Fixes a case where CLI commands that complete with findings (exit 1) could produce duplicate or corrupt JSON output when an unrelated network error occurred during the run. (836ee0d)
- general: Fixes debug-log scrubber so that secrets are consistently masked and scrubbing no longer corrupts the surrounding JSON structure. (d89333a)
- container: Container scans now surface source repository information for locally built images using BuildKit metadata. (dd6ff36)
- deps: Updates dependencies to fix vulnerabilities:
- CVE-2022-25883 (465d5f3)
- CVE-2026-84304 (27f00a1)
- CVE-2026-84375 (5ceea33)
- SNYK-GOLANG-GOLANGORGXCRYPTOSSH-19504090 (4ec3d18)
v1.1307.0
1.1307.0 (2026-08-26)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
- agent: New experimental
snyk agentcommand — a scanning surface built for AI coding agents, with token-optimized output and ergonomics.snyk agent testruns Snyk Open Source, Code, and Secrets together. (b98420c) - secrets:
snyk secrets testnow supports exclusions — add files or paths to theexcludesection of your.snykfile to skip them during secrets scanning. (917bbc5) - container: Container scans now surface image provenance attestations by default, so signed-image provenance metadata appears in results without any extra flag. (0c444b0)
- test: Improves .NET/NuGet scanning —
snyk testcan now analyze already-restored projects fully offline and no longer requires .NET 6 to be installed. (46cf92c) - mcp: The full MCP profile now includes Snyk Secrets. (1d2848e)
- code, secrets: SARIF suppressions now include
reviewedOnandreviewedBymetadata. (5585ea6) - aibom:
snyk aibom test --severity-thresholdnow filters the displayed and JSON results by severity, not only the exit code. (a429c2e)
Bug Fixes
- test: Adds support for scanning pnpm v11
pnpm-lock.yamllockfiles. (a75c5e0) - test: Fixes a crash (
ConcurrentModificationException) when scanning dependencies of Gradle 7.4–8.2 projects. (a0e33f8) - test: Fixes scanning of projects using Hex versions newer than 1.19. (479431a)
- test: Excludes the
.gitfolder from file discovery, preventing intermittent scan failures caused by changes to.gitcontents during a scan. (127db7d)(15fb3a4)) - general: Prevents a possible connection leak when the Snyk API returns an error response. (8fd7d65)
- deps: Updates dependencies to fix vulnerabilities:
- CVE-2026-71557 (fc6181f)
- Updates the Go runtime to address CVE-2026-46600, CVE-2026-56862, CVE-2026-56853, CVE-2026-56860, CVE-2026-56859, and CVE-2026-56858 (1a1ed04)
v1.1306.4
1.1306.4 (2026-08-13)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation
Bug Fixes
- general: Clearer error messages when the CLI cannot reach a configured proxy, including the proxy URL and a specific error code (SNYK-CLI-0028). (a5ebf60)
- deps: Updates dependencies to fix vulnerabilities:
- SNYK-JS-JSYAML-18593780 (d049816)
- Updates the embedded Node.js runtime from 22.22.2 to 22.23.2 and OpenSSL from 3.5.5 to 3.5.7, including fixes for six high-severity CVEs: CVE-2026-45447, CVE-2026-48618, CVE-2026-48933, CVE-2026-56846, CVE-2026-56848, and CVE-2026-58043, plus additional OpenSSL security fixes. (bcf5fec)
v1.1306.3
1.1306.3 (2026-08-05)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation
Bug Fixes
- deps: Updates dependencies to fix vulnerabilities:
- SNYK-JS-SHESCAPE-18319522, CVE-2026-14257 (7366ac1)
- CVE-2026-69152 (0d18508)
v1.1306.2
1.1306.2 (2026-07-27)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation
Bug Fixes
v1.1306.1
1.1306.1 (2026-07-16)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation
Bug Fixes
- deps: Updates dependencies to fix vulnerabilities:
v1.1306.0
1.1306.0 (2026-07-09)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
- doctor: Adds the
snyk doctorcommand to diagnose common CLI problems: generate a diagnostic report for the current system, or analyze debug log output. (ab56a0e) - container: Container scans now detect the Java runtime version across a wider range of JVM base images, and can now find vulnerabilities in .NET application dependencies. (5586aac)
- mcp: The breakability evaluation tool in the Snyk MCP Server is now enabled by default and no longer requires an experimental flag. (56a9196)
- test: Improves dependency detection for Gradle projects. (c819b69)
- redteam: The experimental
snyk redteamcommand has been removed from the CLI, following its deprecation (deprecation date May 31, 2026). (c7d0e3e)
Bug Fixes
- general: Shows a warning when a request is automatically retried due to rate limiting, instead of retrying silently. (f803397)
- general: Skips the reachability upload when no supported files are present, instead of failing. (9ba448c)
- test: Fixes dependency resolution for Swift Package Manager projects that reference packages by registry identity, so they're correctly matched to their GitHub source for vulnerability scanning. (64ac442)
- test: Fixes scanning of sbt projects with custom Scala configurations. (5765a12)
- test: Fixes a bug where scanning Yarn workspaces could report vulnerabilities from a workspace member's dev dependencies as if they were production dependencies, when that member was consumed by a sibling package. (ade08e4)
- test: Gracefully handle missing dotnet CLI during NuGet runtime resolution scans (f61edb3)
- deps: Updates dependencies to fix vulnerabilities: