Skip to content

Releases: snyk/cli

v1.1307.4

Choose a tag to compare

@team-cli-bot team-cli-bot released this 23 Sep 16:00
e7e006e

1.1307.4 (2026-09-23)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features

  • studio: New experimental snyk studio command that sets up Snyk Studio in your AI coding tools (Cursor, Claude Code, Codex, Copilot, Gemini, Kiro, Windsurf), so the code they generate gets scanned in the background as it's written. Run snyk studio install --experimental to get started. (49653c8)
  • fix: New snyk fix --agentic flags to narrow down what gets fixed: --severity-filter fixes only the listed severities, --breakability-filter fixes only Open Source upgrades with the listed breakability, and --exclude-ids fixes everything except the listed issue IDs. (35298ae)
  • fix: snyk fix --agentic now keeps a failed fix's changes by default so you can review them, and reports the fix as failed. Pass --enable-revert to roll the changes back automatically instead. (35298ae)

Bug Fixes

  • test: --iac, --docker, --container and --code no longer get silently dropped for orgs on the unified test API — each now runs the correct scan again instead of an open-source test (which could fail with "No supported files found" or scan the wrong target). (87568ab)

v1.1307.3

Choose a tag to compare

@team-cli-bot team-cli-bot released this 18 Sep 08:01
421c842

1.1307.3 (2026-09-17)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

  • test: Reports an unreadable .snyk policy file as SNYK-POLICY-0002 with a message identifying the problem, instead of an unspecified error. (4ada635)
  • test: --all-projects now resolves each project's .snyk policy from that project's own directory, instead of applying the scan root's policy to every project. (f17550f)
  • test: --scan-all-unmanaged no longer fails with exit code 2 when scanning a directory of JARs with no manifest file. (4f8643b)
  • deps: Updates dependencies to fix vulnerabilities:

v1.1307.2

Choose a tag to compare

@team-cli-bot team-cli-bot released this 09 Sep 15:09
0fda34a

1.1307.2 (2026-09-09)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

v1.1307.1

Choose a tag to compare

@team-cli-bot team-cli-bot released this 07 Sep 14:46
e0bc724

1.1307.1 (2026-09-07)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

  • test: snyk test on a repository with no supported manifest files again reports SNYK-CLI-0008 and exits 3, instead of a generic SNYK-CLI-0000 with exit 2. snyk test --json writes the error document to stdout as expected. (50cad38)
  • test: Restores moduleName, insights.triageAdvice, and functions_new fields in snyk test --json output. (4ec3d18)
  • test: .snyk policy files are now handled correctly in the unified test flow -- empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that previously caused incorrect results or failures. (a22a563)
  • general: Fixes a case where CLI commands that complete with findings (exit 1) could produce duplicate or corrupt JSON output when an unrelated network error occurred during the run. (836ee0d)
  • general: Fixes debug-log scrubber so that secrets are consistently masked and scrubbing no longer corrupts the surrounding JSON structure. (d89333a)
  • container: Container scans now surface source repository information for locally built images using BuildKit metadata. (dd6ff36)
  • deps: Updates dependencies to fix vulnerabilities:

v1.1307.0

Choose a tag to compare

@team-cli-bot team-cli-bot released this 26 Aug 14:15
8e67f44

1.1307.0 (2026-08-26)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features

  • agent: New experimental snyk agent command — a scanning surface built for AI coding agents, with token-optimized output and ergonomics. snyk agent test runs Snyk Open Source, Code, and Secrets together. (b98420c)
  • secrets: snyk secrets test now supports exclusions — add files or paths to the exclude section of your .snyk file to skip them during secrets scanning. (917bbc5)
  • container: Container scans now surface image provenance attestations by default, so signed-image provenance metadata appears in results without any extra flag. (0c444b0)
  • test: Improves .NET/NuGet scanning — snyk test can now analyze already-restored projects fully offline and no longer requires .NET 6 to be installed. (46cf92c)
  • mcp: The full MCP profile now includes Snyk Secrets. (1d2848e)
  • code, secrets: SARIF suppressions now include reviewedOn and reviewedBy metadata. (5585ea6)
  • aibom: snyk aibom test --severity-threshold now filters the displayed and JSON results by severity, not only the exit code. (a429c2e)

Bug Fixes

v1.1306.4

Choose a tag to compare

@team-cli-bot team-cli-bot released this 13 Aug 15:08
98d1b9b

1.1306.4 (2026-08-13)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation

Bug Fixes

  • general: Clearer error messages when the CLI cannot reach a configured proxy, including the proxy URL and a specific error code (SNYK-CLI-0028). (a5ebf60)
  • deps: Updates dependencies to fix vulnerabilities:

v1.1306.3

Choose a tag to compare

@team-cli-bot team-cli-bot released this 06 Aug 12:39
dc7db04

1.1306.3 (2026-08-05)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation

Bug Fixes

v1.1306.2

Choose a tag to compare

@team-cli-bot team-cli-bot released this 27 Jul 15:27
ae94301

1.1306.2 (2026-07-27)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation

Bug Fixes

  • language-server: Improved authentication handling in the Snyk Language Server, which powers Snyk's IDE integrations. (3afb07a)
  • deps: Updates dependencies to fix vulnerabilities:
    • SNYK-GOLANG-GOOGLEGOLANGORGGRPCINTERNALXDSRBAC-18172577 (11d1660)

v1.1306.1

Choose a tag to compare

@team-cli-bot team-cli-bot released this 16 Jul 15:03
fabaafd

1.1306.1 (2026-07-16)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation

Bug Fixes

v1.1306.0

Choose a tag to compare

@team-cli-bot team-cli-bot released this 09 Jul 12:32
d4e9a98

1.1306.0 (2026-07-09)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features

  • doctor: Adds the snyk doctor command to diagnose common CLI problems: generate a diagnostic report for the current system, or analyze debug log output. (ab56a0e)
  • container: Container scans now detect the Java runtime version across a wider range of JVM base images, and can now find vulnerabilities in .NET application dependencies. (5586aac)
  • mcp: The breakability evaluation tool in the Snyk MCP Server is now enabled by default and no longer requires an experimental flag. (56a9196)
  • test: Improves dependency detection for Gradle projects. (c819b69)
  • redteam: The experimental snyk redteam command has been removed from the CLI, following its deprecation (deprecation date May 31, 2026). (c7d0e3e)

Bug Fixes

  • general: Shows a warning when a request is automatically retried due to rate limiting, instead of retrying silently. (f803397)
  • general: Skips the reachability upload when no supported files are present, instead of failing. (9ba448c)
  • test: Fixes dependency resolution for Swift Package Manager projects that reference packages by registry identity, so they're correctly matched to their GitHub source for vulnerability scanning. (64ac442)
  • test: Fixes scanning of sbt projects with custom Scala configurations. (5765a12)
  • test: Fixes a bug where scanning Yarn workspaces could report vulnerabilities from a workspace member's dev dependencies as if they were production dependencies, when that member was consumed by a sibling package. (ade08e4)
  • test: Gracefully handle missing dotnet CLI during NuGet runtime resolution scans (f61edb3)
  • deps: Updates dependencies to fix vulnerabilities: