Last 7 days
0
Features: 0
Changes: 0
Fixes: 0
Deprecations: 0
Developer security platform for code, dependencies, containers, and cloud infrastructure.
Latest Snyk changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Snyk release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
0
3
7
25
Introduce selectable stability levels via multiple deployment channels for the Snyk CLI.
Added user-selectable stability levels for the Snyk CLI via multiple deployment channels
Add multiple deployment channels for the Snyk CLI, allowing users to select a stability level
Introduced selectable deployment channels allowing users to choose CLI stability level.
Introduced deployment channel selection and the new `snyk doctor` diagnostic command; expanded container scanning to detect Java runtimes and .NET dependencies; enabled breakability evaluation by default in MCP.
Bumped Go version to 1.26.4.
Enhanced retry logic to honor X-RateLimit-Reset header when rate limited.
Added deployment channel selection, an "allow incomplete sbom" flag, and an experimental breakability evaluation tool in MCP.
Introduced selectable deployment channel stability levels for the Snyk CLI.
Introduced selectable stability levels for the Snyk CLI via multiple deployment channels.
Added deployment channel selection allowing users to choose stability level for the Snyk CLI.
Adds deployment channel selection with stability levels, new aibom test command, Maven skip wrapper flag, explicit network retry config, and Java runtime binary scanning support.
Added Red Teaming capabilities: profile flag, new terminology, tenant‑based authentication, and interactive setup wizard
Added CLI deployment channel selection allowing users to choose stability level
Added deployment channel selection and a suite of new CLI features: IaC exclude parameter, expanded SBOM fields and scope info, AI BOM upload flag, Red Team result retrieval and HTML reports, MCP package health and profile configuration,...
Added ability for users to select CLI stability level via multiple deployment channels
Introduced deployment channel selection for the Snyk CLI, letting users choose stability levels (documented).
Introduced deployment channel selection for Snyk CLI, allowing users to choose stability levels.
Added deployment channel selection so users can choose a stability level for the Snyk CLI.
Added new container scanning capabilities – Ubuntu Chisel images, zstd‑compressed layers, and a parameter to include system JARs – plus experimental provenance flags for Maven SBOM and DepGraph generation.
Added deployment channel selection for stability levels
Introduce deployment channel selection for CLI stability levels and add experimental AI Red Teaming feature
Added deployment channel selection and several new scanning features (system JARs, TargetOS, Godot, Maven metaversions) plus CVSSv4 links in the IDE
Added support for multiple deployment channels in the Snyk CLI, letting users select a stability level
Added deployment channel selection with stability levels and PAT auto‑region configuration support
Introduced selectable deployment channels for the Snyk CLI with a new public (experimental) command – see documentation
Multiple deployment channels added for the Snyk CLI, letting users select a stability level (with docs).
Added deployment channel selection for the Snyk CLI, letting users choose stability levels (see docs).
Added deployment channel selection for CLI stability levels and raised minimum glibc requirements (2.28 x64, 2.31 arm64) – a breaking change for Linux users.
Added multiple deployment channels for the Snyk CLI, letting users select a stability level
Added deployment channel selection so users can choose CLI stability level
Introduce deployment channel selection for Snyk CLI, letting users choose stability level
Added deployment channel stability selection with documentation
Introduce channel‑based deployment allowing users to select Snyk CLI stability levels
New deployment channel selection for Snyk CLI allowing users to choose stability level (docs added).
Introduce deployment channels allowing users to select stability levels and add unique interaction IDs to errors for better logging.
Introduced multiple deployment channels for the Snyk CLI, allowing users to choose stability levels.
- Added deployment channel selection for the Snyk CLI to choose stability levels
Added support for multiple deployment channels, allowing users to choose CLI stability level.
Adds deployment channel selection for Snyk CLI, allowing users to choose stability levels
Added multi‑channel CLI deployment with selectable stability levels and new features like IAC evidence field, OAuth auto‑detect API URL, and default OSS product for monitor
Introduced multiple deployment channels for Snyk CLI, allowing users to select their desired stability level.
Add deployment channel selection for Snyk CLI, letting users choose stability level.
Fix container handling of RedHat images missing content‑sets attribute
Added CycloneDX 1.6 SBOM generation and related CLI options
Introduce deployment channels for Snyk CLI, letting users select a stability level
Switched Snyk CLI binary distribution to downloads.snyk.io (affecting npm, Homebrew, Scoop and CI/CD integrations) with updated documentation;
Add multiple deployment channels for the Snyk CLI, letting users select their desired stability level
Introduce multiple deployment channels for the Snyk CLI, letting users select a stability level that fits their needs
Add support for selecting CLI stability level via multiple deployment channels
Introduce deployment channels for the Snyk CLI, letting users choose a stability level for their install.
Added deployment channel selection with stability levels, introduced pnpm support via the enablePnpmCli flag, and enabled scanning of npm/yarn projects without lockfiles.
Added configurable deployment channels for Snyk CLI, letting users select stability level
Introduces deployment channels allowing users to select stability levels
Fix error handling in experimental Go native client
Fixed the ls command to trigger re‑analysis after resolving interfile issues.
Corrected the issue path displayed in human‑readable output
Added experimental flag for Snyk code test
Upgrade Snyk IaC test integration to version 0.51.3
Upgrade IAC custom rules extension to address known vulnerabilities
Fixed progress indicator not completing when language server auto-fixes code
Improve sbt console output width
Fix sbom command error when using JSON file output (issue #5136)
Implemented support for CycloneDX version 1.5
Add missing node types in CI pipelines
Added a command to retrieve fix suggestions for Snyk code in the language server
Introduce support for the -dverbose flag when testing Maven projects
Updated CI end‑to‑end tests to use a newer test image.
Added support for optional Python dependencies
Upgrade Slack webhook and ensure dependencies are removed when a parent folder is deleted.
Enable multi‑platform support for OCI images
Fixed language server cache purge issue and upgraded Go toolchain to 1.21.7.
Fixed snyk.scan message range generation in the code scanner (IDE‑134).
Fixed handling of npm dist tags for npm lockfile v2 and newer.
Added support for docker.io registry base in container commands
Fix circular dependency errors for Python packages.
Prevent creation of empty file when using JSON file output in the CLI
Fix handling of large JSON data when writing to file via JSON output
No changelog entries were provided for this release.
No notable changes reported in this release.
Updated Gradle plugin to support Gradle 8.
Fix: Composer lockfile validation now skips invalid PHP lockfiles.
Fixed SARIF bug where the artifactChanges property could not be empty
Fixed authentication handling when a stored token is invalid, preventing errors.
No changelog entries were provided for this release.
Fix CONNECT proxy handling and upgrade needle library
Introduce OAuth Client Credentials Grant support
- Apply bug fixes
Added support for large layers
Fix incorrect version coercion in the container's pip scanner.
Removed the deprecated Managed IaC drift detection feature.
Fixed Python 3.12 support in the Snyk Python plugin.
Updated Snyk NuGet plugin to address multiple bugs
Updated Snyk IaC test to version 0.50.4
Downgraded Needle library to add CONNECT‑mode proxy support.
Fixed bugs by updating the Node.js parser to a newer version.
Added timeout handling to legacy CLI to prevent hangs.
Version 1.1256.0 released.
Updated the Node.js parser to version 1.52.7.
Add Snyk CLI as a generator tool in SBOM documents
Upgrade Snyk IaC test to version 0.50.2
Fix allowing HTTP requests to the local code engine
Add percent‑encoded plus sign handling in purl version tests
Introduce support for accessing global runtime information within features.
Bumped the Gradle plugin to a newer version.
Updated Snyk IaC test dependency (b2682f4).
Update Node.js parser dependency to version 1.52.6.
- Updated goproxy and grpc dependencies to address bugs
Fix .NET v2 parsing to correctly handle missing RID entries.
Fixed configuration handling in the language server extension.
Bumped Node.js parser to version 1.52.4
Fixed bugs related to the NuGet plugin.
Increase the Node.js CLI memory limit to 16 GB.
Increase node memory limit to resolve bug #4921
Fixed bug where invalidSeverityThreshold error was incorrectly shown for HTTP 400 responses.
Add targetRuntime meta information to monitor (bug fix)
Fixed bugs by updating the CODEOWNERS file for lumos and ensuring default HTTP headers are used consistently.
Fix bugs in the release
Fixed Snyk IAC capture to correctly handle empty states.
Fixed injection of TEST SNYK TOKEN variable into workflow steps
Release version 1.1233.0
Removed unintended space in the release JSON output
Added support for passing arguments to SBOM generation
Add support for building macOS arm64 (Apple Silicon) binaries.
Warn when using an insecure HTTP SNYK API URL.
Updated Snyk integration by bumping the NuGet plugin and adding new SBOM options.
Fixed bug where altering the global proxy setting unintentionally affected other configurations.
Bump container CLI extension version
Bump the Snyk NuGet plugin version
No specific changelog entries provided for this release.
Updated Snyk Python plugin package version to 4859.
Fixed critical and high severity vulnerabilities (IDs 4855)
Added integrated IaC naming feature
Added capability to determine the LS protocol version
Upgrade Snyk IaC test to the latest version, improving detection capabilities.
Updated @snyk/code client to version 4.21.0
Fix monorepo sub‑projects overriding the same snapshot issue.
Upgrade Snyk IaC test to return Kubernetes remediation advice
Fix inconsistent telemetry settings
Enhanced the snyk.py installation script.
Inject LS license data into generation pipeline
Introduce SBOM generation support for Maven with extra argument handling
Bump Snyk Docker plugin version to address vulnerabilities
Update Snyk Maven plugin.
Upgrade Snyk IaC test to v0.48.4
Added detailed EvaluationError messages
Add Snyk Maven plugin support for using the Snyk dependency graph
Upgrade Snyk IaC test to the latest version.
Deploy FIPS-compliant binaries for Linux and Windows.
Release version v1.1203.0
Remove the cloud context flag from the feature set
Fix generic assertions for IaC output format tests.
Version bump to 1.1200.0.
Fix: IaC issue resource file is now optional.
Revert native CLI binary build support.
Added native building of CLI binaries
Fixed bugs by bumping the Snyk Docker pull version.
Fixed generic bearer token naming used in bug fixes
Fixed bugs related to client version update.
Fix bugs in the release
Added support for SCM report testing.
Fixed colliding environment variables TOKEN and SNYK_TOKEN.
Release version v1.1190.0 (2023-07-14).
Fixed bundled dependencies behavior
Fixed build image failures reported in issue #4727.
Updated Go language runtime to version 1.20.5.
Add new Snyk IaC test version (4723) to the platform
Remove obsolete process name from user‑agent and fix the environment variable for integration environment name
Fixed SARIF container handling by replacing colon characters in location URIs.
Introduce container SARIF flag support that works without needing a file.
Introduce explicit OS setting
Fix bug in IaC test debugging namespaces
Fix lint test failures
Fixed broken pkg_resources import errors affecting some Python projects.
Add a `--dev` flag to the SBOM command.
Fix bug that prevented Maven aggregate projects from being combined with project names
Added extensive Swift support: CLI monitor logos, CI integration, bashrc and Dockerfile additions, version update, plugin upgrade, test suite, and switched to non-dev Swift snapshot; also removed Swift install steps for CI jobs
Ensure proxy creates missing directories automatically
Version 1.1174.0 released on 2023-06-05.
- Updated SwiftPM to a newer version, addressing related bugs
Add cloud custom rules extension
Add final copy step for deploying Alpine binaries
Reduced binary size by stripping debug symbols
Upgrade Snyk IaC test to version 0.45.0 to fix related issues.
Fix bug in streaming Snyk IAC test functionality.
Fix bug causing publish to latest in S3 to fail (issue #4619).
Add split release workflow capability to the product.
Fix bug that prevented the DISABLE ANALYTICS flag from working correctly.
Improve CLI Yarn performance for Yarn workspaces
Added Snyk IaC rules extension
Added support for alternative environment variable names to disable analytics.
Fix handling of ignored (suppressed) issues
Fix compatibility with the new setuptools on Python 3
Fix outdated type incompatibility
Added output of integrated IaC scan warnings (non-fatal errors).
Removed a feature flag used to toggle between old and new unmanaged service, fixing related bugs.
Respect exit codes for unmanaged processes
Fix custom code client errors and prevent undefined length field access
Limit tests to Extensible CLI
Added support for suppressions in SARIF output.
Fixed bug affecting tar file handling for projects with 'only' flag.
Fix Gradle dependency normalization for transitive dependencies.
Upgrade Snyk IaC test to version 0.43.1
Upgrade Docker plugin version
Fix bug where security tools could terminate installed binaries
Corrected alignment of container SARIF output
- Fixed occasional ETXTBSY errors occurring during CLI runs.
Bumped the Snyk Docker plugin version
Update Node.js parser to version 1.49.0
Added retry logic to sendTestPayload to improve reliability
Fixed an issue where additional CA certificates were not always read.
Fix parsing of Maven output when it contains unresolved properties
Upgrade the NuGet plugin to support large .NET Core projects
Fixed issue where additional report options were not sent to analyzeFolders
Bumped the Node.js parser dependency to version 1.48.3.
Release version v1.1136.0.
Fixed missing "resolve" field in custom rules JSON output
Release version v1.1134.0 published on 2023‑04‑03.
Upgrade Snyk CLI extension to add SBOM support
Fixed help behavior for extensions.
Add IAC Rules Client URL override for Snyk IaC test
Release version v1.1130.0.
Bumped Node.js parser to version 1.48.2.
Bumped Node.js parser dependency to version 1.48.1
Add debug info for failed send test payload request
No changes detailed in this release.
Update Gradle plugin to the latest version
Fixed checksum comparison failure bug
Updated the Snyk C++ plugin to version 2.22.0.
Fix compatibility issues with the latest setuptools version
Version v1.1121.0 released on 2023-03-17.
Fixes issue where the version file was not persisted correctly.
Upgrade Docker plugin to resolve OCI errors
Upgrade Snyk Docker plugin to version 6.0.0
Fixed codeowners update
Bumped the Snyk IaC test dependency to version 0.40.4.
Added extensible CLI available via npm
Reverted the Extensible CLI npm release, undoing the previous rollout.
Redirected specific message output from stdout to stderr.
Fixed bug in organization slugname lookup
Fixed incorrect remediation output for custom rules
Added experimental support for cloud custom rules.
Fixed issue by removing an extra debug parameter
Fixed bug that prevented passing the organization identifier to the code client.
Fixed incorrect return type in code analysis
Fixed entitlement error to show the specific entitlement causing the issue.
Fix ./iac data location issue (commit 106049c)
Add check to avoid uploading an S3 bucket version that already exists; fix missing SDKMAN Java version, pre‑release validation, and Git tag usage errors.
Add support for Gradle daemon usage on Unix-based systems.
Introduce unmanaged SBOM support
Introduces the Extensible CLI packaged for npm
Reverted the Extensible CLI release via npm, removing npm distribution.
Introduce feature to use current date when creating filenames
Introduces an extensible CLI distributed via npm, enabling custom extensions.
Fix test scope handling in Maven aggregate projects.
Improve deployment testing capabilities.
Upgraded Snyk IaC test tool to version 0.39.0.
No change details provided for this release.
Upgrade Snyk IaC test to version 0.38.0
Fix host URL handling for instances across regions
Added support for uploading .snyk files via the code client
Release version v1.1090.0.
Fixed concurrency issues during initialization
No change details provided.
Fix .build path handling and exclusion (ensure .build is treated as end of path, exclude .build folder, and ignore .build during Swift searches)
Fix parsing of remote URLs set by actions/checkokut.
Pass OAuth token to SAST when available
Update Snyk IaC test to version v0.37.3
Fixed container Python distribution package support.
Added logic to ignore unsupported package managers during snyk monitor runs
Version bump to v1.1081.0
Fix: merge internal and external defined no proxy handling
Release version 1.1079.0.
Fix missing organization slug in query string for IaC scan usage tracking
Add no-proxy handling for localhost traffic, preventing it from being proxied
Reverted the previous merge that added the Golang CLI for Linux
No changelog details provided.
Introduce unmanaged analytics capability.
Add Yarn lock v2 support and related improvements
Fixed crash caused by 'self' being undefined.
Release version v1.1071.0 (as titled).
Introduce a feature flag to disable container app scanning
Fix checksum-based package search to use the /rest/packages endpoint.
Fixed OOM errors by using JSON.parse for data processing
Upgrade the HTTP client library to a newer version.
Fix issue where local socket requests were not being proxied.
Fix merging of scopes in sbt projects
Fix escaping of child process arguments to handle special characters correctly
Set base64 as the default encoding for SAST analysis.
Fix bug by using lenient config in the Gradle plugin
Upgrade Snyk IaC test to version 0.37.0
Updated Snyk Docker plugin to fix bugs
Updated Snyk Gradle plugin to version 3.24.5.
Upgrade Snyk IaC test to v0.36.5
- No changes recorded for this release.
Fix issue with Go file path resolution
Restored environment proxy support for launching Snyk IAC tests.
Update the Snyk Docker plugin to the latest version
Resolved certificate verification problem in the Go plugin.
Improved error messages when using cloud context