Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion pkg/configuration/configuration.go
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,6 @@ func readConfigFilesIntoViper(files []string, config *extendedViper) {
}

config.viper.AddConfigPath(configPath)
config.viper.AddConfigPath(".")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

what other implications this removal can have?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I am not noticing any other files besides snyk referenced for the config (

)

Also, because of

config.viper.SetConfigName(file)
this function always seems to load only the last file from the array. I believe we could also remove the for loop.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

does this affect .snyk files? Should the behavior consider the current directory, same behavior as happens for .gitignore?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

also need to think:

  1. What if there are customers using the current approach? This will be a breaking change for them.

I also think should contain more tests, i.e. not only look for snyk.json, but for others (.snyk, .gitignore, ...)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I see the ticket is a bit old, so I wonder if the understanding there remains the same

@octavian-snyk octavian-snyk Jul 17, 2026 •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

.snyk and .gitignore shouldn't be affected. 😀

The config is managed by Viper while .snyk and .gitignore seem to be loaded here:

if filepath.Base(ignoreFile) == ".snyk" { // .snyk files are yaml files and should be parsed differently

Tests regarding their loading seems to be performed here: https://github.com/snyk/go-application-framework/blob/main/pkg/utils/file_filter_test.go

I am not sure if we should consider this a breaking change or simply a fix. 😔
TS CLI commands (e.g.: test, container, iac) never loaded the local directory snyk.json config file. The behavior of snyk commands regarding it is currently inconsistent.


// read config files
//nolint:errcheck // breaking api change needed to fix this
Expand Down
59 changes: 59 additions & 0 deletions pkg/configuration/configuration_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -1178,6 +1178,65 @@ func Test_ReloadConfig(t *testing.T) {
cleanupConfigstore(t)
}

func Test_Configuration_doesNotLoadSnykJsonFromWorkingDirectory(t *testing.T) {
fakeHome := t.TempDir()
projectDir := t.TempDir()

t.Setenv("HOME", fakeHome)
t.Setenv("USERPROFILE", fakeHome)

cwdConfig := filepath.Join(projectDir, "snyk.json")
err := os.WriteFile(cwdConfig, []byte(`{
"api": "local-dir-token",
"org": "dir-org",
"endpoint": "https://api.invalid/api"
}`), 0o600)
assert.NoError(t, err)

oldWd, err := os.Getwd()
assert.NoError(t, err)
assert.NoError(t, os.Chdir(projectDir))
t.Cleanup(func() {
assert.NoError(t, os.Chdir(oldWd))
})

config := New()

assert.Empty(t, config.GetString("api"))
assert.Empty(t, config.GetString("org"))
assert.Empty(t, config.GetString("endpoint"))
}

func Test_Configuration_loadsSnykJsonFromConfigstoreNotWorkingDirectory(t *testing.T) {
fakeHome := t.TempDir()
projectDir := t.TempDir()

t.Setenv("HOME", fakeHome)
t.Setenv("USERPROFILE", fakeHome)

configstoreDir := filepath.Join(fakeHome, ".config", "configstore")
assert.NoError(t, os.MkdirAll(configstoreDir, 0o700))
assert.NoError(t, os.WriteFile(filepath.Join(configstoreDir, "snyk.json"), []byte(`{
"api": "home-token",
"org": "my-org",
"endpoint": "https://api.example/api"
}`), 0o600))
assert.NoError(t, os.WriteFile(filepath.Join(projectDir, "snyk.json"), []byte(`{"api":"bad-token"}`), 0o600))

oldWd, err := os.Getwd()
assert.NoError(t, err)
assert.NoError(t, os.Chdir(projectDir))
t.Cleanup(func() {
assert.NoError(t, os.Chdir(oldWd))
})

config := New()

assert.Equal(t, "home-token", config.GetString("api"))
assert.Equal(t, "my-org", config.GetString("org"))
assert.Equal(t, "https://api.example/api", config.GetString("endpoint"))
}

func Test_EmptyStorage(t *testing.T) {
s := &EmptyStorage{}
assert.NoError(t, s.Set("k", "v"))
Expand Down