From aa0e5bf5ab85267f6d9028c823e0fb01dd3751b5 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:11:16 +0200 Subject: [PATCH 01/30] docs(code): .gitignore excludes only untracked files from September 14 Co-Authored-By: Claude Opus 5 (1M context) --- scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md index 1baec6e12950..f082f11eac12 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md @@ -16,7 +16,7 @@ Snyk Code is a developer-first static application security testing (SAST) soluti The following table shows the Snyk Code features, including analysis, managing security issues in your code, and facilitating remediations within your development environment. -
FeatureDescription
Issue filtering, sorting, and grouping

To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria.

See Filter existing Projects.

Priority Score

Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score.

See Priority score.

Data flow

Visualize the path of the issue from source to sink with a step-by-step flow.

See Data flow.

Vulnerability

Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it.

See Manage code vulnerabilities

Fix analysis

Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows.

See Breakdown of Code analysis.

Create Jira issue

Track and export Snyk issues to your Jira project.

See Create a Jira issue.

Ignore issues

Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it.

See Ignore issues.

Exclude files from the import process

Check for DeepCode/Snyk ignore files .gitignore .dcignore and read them if they exist. Using the information in these files, Snyk filters to identify only the files with the supported extensions in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk. ,gitignore exclusions are honored by the snyk code test CLI command.

See also Exclude directories and files from the import process.

Interfile analysisThis is available for all languages supported by Snyk Code except Ruby.
+
FeatureDescription
Issue filtering, sorting, and grouping

To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria.

See Filter existing Projects.

Priority Score

Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score.

See Priority score.

Data flow

Visualize the path of the issue from source to sink with a step-by-step flow.

See Data flow.

Vulnerability

Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it.

See Manage code vulnerabilities

Fix analysis

Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows.

See Breakdown of Code analysis.

Create Jira issue

Track and export Snyk issues to your Jira project.

See Create a Jira issue.

Ignore issues

Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it.

See Ignore issues.

Exclude files from the import process

Check for DeepCode/Snyk ignore files .gitignore .dcignore and read them if they exist. Using the information in these files, Snyk filters to identify only the files with the supported extensions in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk.

From September 14, 2026, .gitignore rules exclude only files that are untracked, matching the behavior of Git itself. Files committed to the repository are analyzed even when a .gitignore rule matches them. This applies to Snyk Code and Snyk Secrets across all interfaces and cannot be disabled. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Use .snyk exclude patterns to deliberately exclude a path.

See also Exclude directories and files from the import process.

Interfile analysisThis is available for all languages supported by Snyk Code except Ruby.
## Deployment From 066a5779f18a5b4535c3b6e6196b4591ee095dcc Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:24:35 +0200 Subject: [PATCH 02/30] docs(code): document template file analysis for cross-site scripting Co-Authored-By: Claude Opus 5 (1M context) --- .../technical-specifications-and-guidance.md | 8 ++++++++ scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md | 1 + 2 files changed, 9 insertions(+) diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index 7f78e6db1df7..0fe59ea1cb99 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -72,6 +72,14 @@ Partial support includes: Snyk continuously expands its framework coverage and improves analysis accuracy. +### Template file analysis + +Snyk Code analyzes template files together with the application code that renders them. Data that reaches a template from your application code is followed into the template, so a cross-site scripting issue that becomes exploitable only where the template writes its output is reported. The reported data flow spans both the application code and the template. + +Snyk Code takes the escaping behavior of the template engine into account. Output written through the default escaping of the engine is not reported. Output written through a construct that bypasses escaping, such as a raw or unescaped directive, is treated as a sink. + +Template file analysis applies to the template engines that Snyk Code supports, and Snyk is expanding that coverage. If a template engine you use is not yet covered, [contact Snyk Support](https://support.snyk.io). + ### How Snyk Code analysis works Snyk scans your codebase following this sequence: diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md index f082f11eac12..27fc0893332d 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md @@ -39,6 +39,7 @@ Snyk Code is powered by a semantic, AI-based analysis engine and can analyze the
Hardcoded secret found

Hardcoded secret found

* Point-to analysis: Identifies multiple potential issues, including buffer overruns, null dereferences, and type mismatches, by modeling memory use in variables and references. +* Template files: Follows data from your application code into the template that renders it, so cross-site scripting that becomes exploitable only at the point of rendering is reported. See [Template file analysis](https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/technical-specifications-and-guidance#template-file-analysis). * Type inference: Determines the initial type and its changes. This is of special interest for dynamically typed languages. * Value ranges: Infers possible values for variables used to call functions to track off-by-one errors in arrays, division-by-zero errors, and null dereferences. From 6c1b3e8f09fc7c0c9c4ca423a2fbee036a9f3cd8 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:24:48 +0200 Subject: [PATCH 03/30] docs(code): Java analysis supports Java SE 25 Co-Authored-By: Claude Opus 5 (1M context) --- .../java-and-kotlin/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index a2151d9e199e..9b1c16fecb0a 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -26,7 +26,7 @@ Improved Gradle SCM scanning is in Early Access. For more information, see [SCM ## Technical specifications -Snyk supports Java analysis for Java versions up to SE 21 and is designed to process code from newer Java versions where feasible. +Snyk supports Java analysis for Java versions up to SE 25 and is designed to process code from newer Java versions where feasible. ### Supported frameworks and libraries From f3f82656a4b2530de8987661d5027094040a834e Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:25:33 +0200 Subject: [PATCH 04/30] docs(code): add Java framework and library coverage, including Hybris FlexibleSearch Co-Authored-By: Claude Opus 5 (1M context) --- .../java-and-kotlin/README.md | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index 9b1c16fecb0a..b0c69137cce3 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -38,6 +38,8 @@ For Java and Kotlin, the following frameworks and libraries are supported: * Android Standard Library * Apache Camel * Apache Commons +* Apache Commons Collections +* Apache CXF * Apache Tomcat * Apache XML * apache.mahou @@ -50,7 +52,10 @@ For Java and Kotlin, the following frameworks and libraries are supported: * Dropwizard * elasticsearch * FasterXML Jackson +* Flyway +* Google API Client * Google Guava +* Google OAuth Client * grpc-java * hibernate * http4k @@ -64,6 +69,7 @@ For Java and Kotlin, the following frameworks and libraries are supported: * Java Standard Edition * javalin * Jax-RS +* JAXB * Jolokia * jooq {% endcolumn %} @@ -72,6 +78,7 @@ For Java and Kotlin, the following frameworks and libraries are supported: * Kyro * Micronaut * mongo-java-driver +* MSAL4J * Netty * okhttp3 * org.apache.hc.client5 @@ -82,12 +89,14 @@ For Java and Kotlin, the following frameworks and libraries are supported: * org.dom4j.io * Playframework * rxhttp +* SAP Commerce (Hybris) * Seam logger * SnakeYaml * Spongycastle * Spring AI * Spring boot * Spring Cloud Config +* Spring Security OAuth2 Client * Spring Web, MVC and JDBC * Spring WebFlux * Struts @@ -107,6 +116,8 @@ Kotlin only: {% endcolumn %} {% endcolumns %} +For SAP Commerce (Hybris), Snyk Code analyzes FlexibleSearch queries for SQL injection. This is supported for Java only. Values supplied through query parameter binding are recognized as safe and are not reported. + ### Supported package managers and package registries * Supported package managers: [Maven](https://maven.apache.org) and [Gradle](https://gradle.org), with the following supported versions: From c281b6b9bfcfc8b669b406c144625ab6e20e3317 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:25:52 +0200 Subject: [PATCH 05/30] docs(code): LangChain LiteLLM is an untrusted data source for Python Co-Authored-By: Claude Opus 5 (1M context) --- .../supported-languages-list/python/README.md | 3 +++ 1 file changed, 3 insertions(+) diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index 92de503ec89d..caeba7e36010 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -56,6 +56,7 @@ For Python, the following frameworks and libraries are supported: * huggingface\_hub * iopg * LangChain +* LangChain LiteLLM * ldap3 * libxml * lxml @@ -87,6 +88,8 @@ For Python, the following frameworks and libraries are supported: {% endcolumn %} {% endcolumns %} +Snyk Code treats data returned through LangChain LiteLLM as untrusted, so model output that reaches a sink is reported in the same way as any other untrusted input. + ### Serverless support Snyk Code analyzes Python functions that run on AWS Lambda. Snyk resolves handlers from AWS SAM and Serverless Framework configuration files, so it analyzes the function entry point as application code instead of skipping it. From 57ca7c1ef6c4fd2ef014bf81bb5fcf7586251888 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 20 Aug 2026 12:26:41 +0200 Subject: [PATCH 06/30] docs: add September 2026 Snyk Code and Snyk Secrets updates to What's new Co-Authored-By: Claude Opus 5 (1M context) --- discover-snyk/whats-new.md | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md index 5a56542ad25e..667a53870474 100644 --- a/discover-snyk/whats-new.md +++ b/discover-snyk/whats-new.md @@ -9,6 +9,21 @@ nav_context: new The most recent updates include significant changes to the user docs, such as features added or removed, structural changes that affect how you find relevant information, and other improvements to enhance your interaction with the Snyk knowledge base. +## September 2026 + +### Snyk Code + +* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. +* Java analysis now covers Java SE 25. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. +* Java framework and library coverage was added or improved for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. SAP Commerce (Hybris) FlexibleSearch queries are analyzed for SQL injection, with parameter binding recognized as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. +* LangChain LiteLLM is recognized as a source of untrusted data in Python. Visit [Python](https://docs.snyk.io/supported-languages/supported-languages-list/python) for more details. +* Rule coverage was extended for Java, Kotlin, C#, Go, JavaScript, and PHP, with additional sources, sinks, and unsafe API patterns, in particular for cryptography. Nothing needs to be enabled and no configuration changes. Expect additional findings in code that was already being scanned. Visit [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) for more details. +* From September 14, 2026, `.gitignore` rules exclude only untracked files, matching the behavior of Git itself. Files committed to the repository are analyzed even when a `.gitignore` rule matches them, which increases the number of files in scope and therefore the number of findings. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. + +### Snyk Secrets + +* From September 14, 2026, secrets are detected in files committed to the repository even when a `.gitignore` rule matches them. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. + ## August 2026 ### Snyk supported languages From 71b2de3e390967cacc7baaaab8ec939434b9e970 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Tue, 8 Sep 2026 16:40:54 +0100 Subject: [PATCH 07/30] docs(code): template file analysis covers every language and template engine combination Co-Authored-By: Claude Opus 5 (1M context) --- .../technical-specifications-and-guidance.md | 6 ++++-- discover-snyk/whats-new.md | 2 +- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index 0fe59ea1cb99..0046e036c6c6 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -74,11 +74,13 @@ Snyk continuously expands its framework coverage and improves analysis accuracy. ### Template file analysis -Snyk Code analyzes template files together with the application code that renders them. Data that reaches a template from your application code is followed into the template, so a cross-site scripting issue that becomes exploitable only where the template writes its output is reported. The reported data flow spans both the application code and the template. +Snyk Code analyzes template files together with the application code that renders them. Data that reaches a template from your application code is followed into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template writes its output is reported. The reported data flow spans both the application code and the template. Snyk Code takes the escaping behavior of the template engine into account. Output written through the default escaping of the engine is not reported. Output written through a construct that bypasses escaping, such as a raw or unescaped directive, is treated as a sink. -Template file analysis applies to the template engines that Snyk Code supports, and Snyk is expanding that coverage. If a template engine you use is not yet covered, [contact Snyk Support](https://support.snyk.io). +A template is analyzed independently of the language that renders it. Every template engine that Snyk Code supports is analyzed in every language that Snyk Code supports, so no combination of language and template engine is excluded. Template files are analyzed in addition to the source file formats listed for each language in [Supported languages, package managers, and frameworks](supported-languages-package-managers-and-frameworks.md). + +Snyk is expanding template engine coverage. If a template engine you use is not yet covered, [contact Snyk Support](https://support.snyk.io). ### How Snyk Code analysis works diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md index 667a53870474..f51f1e03d1ea 100644 --- a/discover-snyk/whats-new.md +++ b/discover-snyk/whats-new.md @@ -13,7 +13,7 @@ The most recent updates include significant changes to the user docs, such as fe ### Snyk Code -* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. +* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Every template engine Snyk Code supports is analyzed in every language Snyk Code supports. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. * Java analysis now covers Java SE 25. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. * Java framework and library coverage was added or improved for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. SAP Commerce (Hybris) FlexibleSearch queries are analyzed for SQL injection, with parameter binding recognized as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. * LangChain LiteLLM is recognized as a source of untrusted data in Python. Visit [Python](https://docs.snyk.io/supported-languages/supported-languages-list/python) for more details. From 011066a43151494a5814383e16312fff89b6a36c Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Tue, 8 Sep 2026 17:33:55 +0100 Subject: [PATCH 08/30] docs(code): document the supported template engine and language pairs Co-Authored-By: Claude Opus 5 (1M context) --- .../java-and-kotlin/README.md | 15 +++++++++++++++ .../supported-languages-list/.net/README.md | 11 +++++++++++ .../supported-languages-list/c-c++.md | 10 ++++++++++ .../supported-languages-list/go.md | 10 ++++++++++ .../supported-languages-list/groovy.md | 12 ++++++++++++ .../javascript/README.md | 13 +++++++++++++ .../supported-languages-list/php.md | 12 ++++++++++++ .../supported-languages-list/python/README.md | 11 +++++++++++ .../supported-languages-list/ruby.md | 10 ++++++++++ .../supported-languages-list/scala.md | 15 +++++++++++++++ .../swift-and-objective-c.md | 10 ++++++++++ .../supported-languages-list/typescript.md | 13 +++++++++++++ .../technical-specifications-and-guidance.md | 19 ++++++++++++++++--- discover-snyk/whats-new.md | 2 +- 14 files changed, 159 insertions(+), 4 deletions(-) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index b0c69137cce3..279e6f00ccf0 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -140,6 +140,21 @@ Available features: * Interfile analysis - Kotlin is fully supported * Interfile analysis - Android is partially supported +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Java and Kotlin, Snyk Code supports the following template engines: + +* FreeMarker +* Handlebars +* Mustache +* Pug +* Thymeleaf +* Velocity + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../supported-languages/technical-specifications-and-guidance.md#template-file-analysis). + ## Java and Kotlin for Snyk Open Source For Java and Kotlin with Snyk Open Source, the following file formats are supported: diff --git a/discover-snyk/supported-languages/supported-languages-list/.net/README.md b/discover-snyk/supported-languages/supported-languages-list/.net/README.md index 38c7a5d62b47..a82ca758f9fa 100644 --- a/discover-snyk/supported-languages/supported-languages-list/.net/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/.net/README.md @@ -44,6 +44,17 @@ For .NET with Snyk Code, the following frameworks and libraries are supported: * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For C# and VB.NET, Snyk Code supports the following template engines: + +* Mustache +* Razor + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). + ## .NET for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/supported-languages-list/c-c++.md b/discover-snyk/supported-languages/supported-languages-list/c-c++.md index e4d35d668a73..d1e641248bd3 100644 --- a/discover-snyk/supported-languages/supported-languages-list/c-c++.md +++ b/discover-snyk/supported-languages/supported-languages-list/c-c++.md @@ -79,6 +79,16 @@ For C/C++ Projects: When using the IDE, you do not need additional options. The Snyk plugin displays results in the IDE views. +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For C/C++, Snyk Code supports the following template engines: + +* Mustache + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## C/C++ for Snyk Open Source ### Available features diff --git a/discover-snyk/supported-languages/supported-languages-list/go.md b/discover-snyk/supported-languages/supported-languages-list/go.md index 09ffe92ce07a..6aaa9bc88fbe 100644 --- a/discover-snyk/supported-languages/supported-languages-list/go.md +++ b/discover-snyk/supported-languages/supported-languages-list/go.md @@ -51,6 +51,16 @@ Available features: * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Go, Snyk Code supports the following template engines: + +* Mustache + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## Go for Snyk Open Source ### Available features diff --git a/discover-snyk/supported-languages/supported-languages-list/groovy.md b/discover-snyk/supported-languages/supported-languages-list/groovy.md index 50d392ab7288..7df5f4411594 100644 --- a/discover-snyk/supported-languages/supported-languages-list/groovy.md +++ b/discover-snyk/supported-languages/supported-languages-list/groovy.md @@ -40,3 +40,15 @@ For Groovy, Snyk supports the following file extensions: * Support for Interfile analysis * Reports + +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Groovy, Snyk Code supports the following template engines: + +* FreeMarker +* Thymeleaf +* Velocity + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). diff --git a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md index 2d142730304a..251811ee25ff 100644 --- a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md @@ -109,6 +109,19 @@ The following file formats are supported: `.ejs`, `.es`, `.es6`, `.htm`, `.html` * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For JavaScript, Snyk Code supports the following template engines: + +* EJS +* Handlebars +* Mustache +* Pug + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). + ## JavaScript for Snyk Open Source ### Supported package managers and package registries diff --git a/discover-snyk/supported-languages/supported-languages-list/php.md b/discover-snyk/supported-languages/supported-languages-list/php.md index 2d74a06e73e3..b6c4d65c3ee5 100644 --- a/discover-snyk/supported-languages/supported-languages-list/php.md +++ b/discover-snyk/supported-languages/supported-languages-list/php.md @@ -37,6 +37,18 @@ For PHP, the following frameworks and libraries are supported: The following file formats are supported: `.php`, `.phtml`, `.module`, `.inc`, `.install`, `.theme`, `.profile`. +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For PHP, Snyk Code supports the following template engines: + +* Mustache +* Pug +* Twig + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## PHP for Snyk Open Source For PHP with Snyk Open Source, PHP versions 5.2 through 8.5 are supported. diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index caeba7e36010..bcfab77a9266 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -112,6 +112,17 @@ Snyk Code relies on Python projects to follow a standard directory layout for ac Both `src-layout` and `flat-layout` are supported. Proper adherence to these conventions allows the scanner to trace code effectively and provide accurate results. +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Python, Snyk Code supports the following template engines: + +* Jinja2 +* Mustache + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). + ## Python for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/supported-languages-list/ruby.md b/discover-snyk/supported-languages/supported-languages-list/ruby.md index 6f60a43d1fca..d02e3ecc5f9e 100644 --- a/discover-snyk/supported-languages/supported-languages-list/ruby.md +++ b/discover-snyk/supported-languages/supported-languages-list/ruby.md @@ -70,6 +70,16 @@ Available features: * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Ruby, Snyk Code supports the following template engines: + +* Mustache + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## Ruby for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/supported-languages-list/scala.md b/discover-snyk/supported-languages/supported-languages-list/scala.md index 0ed0f5f0f8e8..851253b1be54 100644 --- a/discover-snyk/supported-languages/supported-languages-list/scala.md +++ b/discover-snyk/supported-languages/supported-languages-list/scala.md @@ -57,6 +57,21 @@ The **Snyk Fix PR** feature is not available for Swift and Objective-C. This mea * "**Fixed in" available** is set to **Yes.** {% endhint %} +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Scala, Snyk Code supports the following template engines: + +* FreeMarker +* Handlebars +* Mustache +* Pug +* Thymeleaf +* Velocity + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## Scala for Snyk Open Source For Scala with Snyk Open Source, the following file format is supported: `build.sbt` diff --git a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md index 0d0e634f7ca0..d23fd998ae72 100644 --- a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md +++ b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md @@ -80,6 +80,16 @@ For Objective-C, Snyk supports `.m` files, and implicitly supports `.h` files. * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For Swift and Objective-C, Snyk Code supports the following template engines: + +* Mustache + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## Swift and Objective-C for Snyk Open Source For Swift with Snyk Open Source, Snyk supports Swifts versions from 3.0 up to 6.2.x. diff --git a/discover-snyk/supported-languages/supported-languages-list/typescript.md b/discover-snyk/supported-languages/supported-languages-list/typescript.md index 6359a9c3db74..2ae1bf756202 100644 --- a/discover-snyk/supported-languages/supported-languages-list/typescript.md +++ b/discover-snyk/supported-languages/supported-languages-list/typescript.md @@ -46,6 +46,19 @@ Available features: * Reports * Interfile analysis +### Template file analysis + +Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. + +For TypeScript, Snyk Code supports the following template engines: + +* EJS +* Handlebars +* Mustache +* Pug + +For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). + ## TypeScript for Snyk Open Source For TypeScript with Snyk Open Source, the following file formats are supported: diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index 0046e036c6c6..f7c642252862 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -78,9 +78,22 @@ Snyk Code analyzes template files together with the application code that render Snyk Code takes the escaping behavior of the template engine into account. Output written through the default escaping of the engine is not reported. Output written through a construct that bypasses escaping, such as a raw or unescaped directive, is treated as a sink. -A template is analyzed independently of the language that renders it. Every template engine that Snyk Code supports is analyzed in every language that Snyk Code supports, so no combination of language and template engine is excluded. Template files are analyzed in addition to the source file formats listed for each language in [Supported languages, package managers, and frameworks](supported-languages-package-managers-and-frameworks.md). - -Snyk is expanding template engine coverage. If a template engine you use is not yet covered, [contact Snyk Support](https://support.snyk.io). +Support is defined by the pairing of a template engine with the language that renders the template. The following pairs are supported. Template files are analyzed in addition to the source file formats listed for each language. + +| Template engine | File extensions | Languages | +| :--- | :--- | :--- | +| EJS | `.ejs` | JavaScript, TypeScript | +| FreeMarker | `.ftl`, `.ftlh` | Java, Kotlin, Scala, Groovy | +| Handlebars | `.hbs`, `.handlebars` | JavaScript, TypeScript, Java, Kotlin, Scala | +| Jinja2 | `.j2`, `.jinja`, `.jinja2` | Python | +| Mustache | `.mustache` | JavaScript, TypeScript, Java, Kotlin, Scala, Python, Ruby, PHP, C#, VB.NET, Go, C/C++, Swift, Objective-C | +| Pug | `.pug`, `.jade` | JavaScript, TypeScript, Java, Kotlin, Scala, PHP | +| Razor | `.cshtml`, `.razor`, `.vbhtml` | C#, VB.NET | +| Thymeleaf | `.html`, `.xml` | Java, Kotlin, Scala, Groovy | +| Twig | `.twig`, `.html.twig` | PHP | +| Velocity | `.vm`, `.vtl` | Java, Kotlin, Scala, Groovy | + +Snyk is expanding this coverage. If a template engine or a pair you use is not listed, [contact Snyk Support](https://support.snyk.io). ### How Snyk Code analysis works diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md index f51f1e03d1ea..05835308bafe 100644 --- a/discover-snyk/whats-new.md +++ b/discover-snyk/whats-new.md @@ -13,7 +13,7 @@ The most recent updates include significant changes to the user docs, such as fe ### Snyk Code -* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Every template engine Snyk Code supports is analyzed in every language Snyk Code supports. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. +* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Each supported template engine is analyzed in the languages it is supported with. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. * Java analysis now covers Java SE 25. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. * Java framework and library coverage was added or improved for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. SAP Commerce (Hybris) FlexibleSearch queries are analyzed for SQL injection, with parameter binding recognized as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. * LangChain LiteLLM is recognized as a source of untrusted data in Python. Visit [Python](https://docs.snyk.io/supported-languages/supported-languages-list/python) for more details. From 44e5ca57d85528b5b43a592523d880d3f41ceab0 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Thu, 10 Sep 2026 15:15:51 +0100 Subject: [PATCH 09/30] docs(code): add Mako to the Python template engine pairs Co-Authored-By: Claude Opus 5 (1M context) --- .../supported-languages-list/python/README.md | 1 + .../supported-languages/technical-specifications-and-guidance.md | 1 + 2 files changed, 2 insertions(+) diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index bcfab77a9266..fdf03d802717 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -119,6 +119,7 @@ Snyk Code parses template files and follows data from your application code into For Python, Snyk Code supports the following template engines: * Jinja2 +* Mako * Mustache For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index f7c642252862..8b549105042e 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -86,6 +86,7 @@ Support is defined by the pairing of a template engine with the language that re | FreeMarker | `.ftl`, `.ftlh` | Java, Kotlin, Scala, Groovy | | Handlebars | `.hbs`, `.handlebars` | JavaScript, TypeScript, Java, Kotlin, Scala | | Jinja2 | `.j2`, `.jinja`, `.jinja2` | Python | +| Mako | `.mako`, `.mak` | Python | | Mustache | `.mustache` | JavaScript, TypeScript, Java, Kotlin, Scala, Python, Ruby, PHP, C#, VB.NET, Go, C/C++, Swift, Objective-C | | Pug | `.pug`, `.jade` | JavaScript, TypeScript, Java, Kotlin, Scala, PHP | | Razor | `.cshtml`, `.razor`, `.vbhtml` | C#, VB.NET | From cd8163b9c4d0b4b62e3b4950e4f47b57f1435947 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:44:36 +0300 Subject: [PATCH 10/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/go.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/go.md b/discover-snyk/supported-languages/supported-languages-list/go.md index 6aaa9bc88fbe..27e15f41357a 100644 --- a/discover-snyk/supported-languages/supported-languages-list/go.md +++ b/discover-snyk/supported-languages/supported-languages-list/go.md @@ -53,7 +53,7 @@ Available features: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Go, Snyk Code supports the following template engines: From a9a0a22e500c57d2798ed911b79647240dd95627 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:45:11 +0300 Subject: [PATCH 11/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/.net/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/.net/README.md b/discover-snyk/supported-languages/supported-languages-list/.net/README.md index a82ca758f9fa..ffcf39cb567e 100644 --- a/discover-snyk/supported-languages/supported-languages-list/.net/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/.net/README.md @@ -46,7 +46,7 @@ For .NET with Snyk Code, the following frameworks and libraries are supported: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For C# and VB.NET, Snyk Code supports the following template engines: From 0eeb38927bef9c52c846892838aaff4b46ca6e30 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:46:24 +0300 Subject: [PATCH 12/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/c-c++.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/c-c++.md b/discover-snyk/supported-languages/supported-languages-list/c-c++.md index d1e641248bd3..ac29026615c7 100644 --- a/discover-snyk/supported-languages/supported-languages-list/c-c++.md +++ b/discover-snyk/supported-languages/supported-languages-list/c-c++.md @@ -81,7 +81,7 @@ When using the IDE, you do not need additional options. The Snyk plugin displays ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For C/C++, Snyk Code supports the following template engines: From 69b5b93dfc847bedda6ac34b07b49e35269e4097 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:46:42 +0300 Subject: [PATCH 13/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/groovy.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/groovy.md b/discover-snyk/supported-languages/supported-languages-list/groovy.md index 7df5f4411594..9601310c6e4a 100644 --- a/discover-snyk/supported-languages/supported-languages-list/groovy.md +++ b/discover-snyk/supported-languages/supported-languages-list/groovy.md @@ -43,7 +43,7 @@ For Groovy, Snyk supports the following file extensions: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Groovy, Snyk Code supports the following template engines: From cf4f01ee33582c17d90fe181184439dfd7ecb089 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:47:56 +0300 Subject: [PATCH 14/30] docs(code): tighten passive voice per style guide --- .../supported-languages-list/javascript/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md index 251811ee25ff..78c93f78cf5d 100644 --- a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md @@ -111,7 +111,7 @@ The following file formats are supported: `.ejs`, `.es`, `.es6`, `.htm`, `.html` ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For JavaScript, Snyk Code supports the following template engines: From bc6cd7675f02352bca83bc273bc0fa1cd3c2324e Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:48:22 +0300 Subject: [PATCH 15/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/php.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/php.md b/discover-snyk/supported-languages/supported-languages-list/php.md index b6c4d65c3ee5..10e713341aa9 100644 --- a/discover-snyk/supported-languages/supported-languages-list/php.md +++ b/discover-snyk/supported-languages/supported-languages-list/php.md @@ -39,7 +39,7 @@ The following file formats are supported: `.php`, `.phtml`, `.module`, `.inc`, ` ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For PHP, Snyk Code supports the following template engines: From 30c1c5470b8707112a743de0a1d065bd519eecaf Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:48:51 +0300 Subject: [PATCH 16/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/ruby.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/ruby.md b/discover-snyk/supported-languages/supported-languages-list/ruby.md index d02e3ecc5f9e..118f5204c1f6 100644 --- a/discover-snyk/supported-languages/supported-languages-list/ruby.md +++ b/discover-snyk/supported-languages/supported-languages-list/ruby.md @@ -72,7 +72,7 @@ Available features: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Ruby, Snyk Code supports the following template engines: From e0ef0c83a4c26f0e703536d337f5ffe1ab9c9bbc Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:49:23 +0300 Subject: [PATCH 17/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/scala.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/scala.md b/discover-snyk/supported-languages/supported-languages-list/scala.md index 851253b1be54..f95f33c4b78a 100644 --- a/discover-snyk/supported-languages/supported-languages-list/scala.md +++ b/discover-snyk/supported-languages/supported-languages-list/scala.md @@ -59,7 +59,7 @@ The **Snyk Fix PR** feature is not available for Swift and Objective-C. This mea ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Scala, Snyk Code supports the following template engines: From 7920fa96d9ec43cdf2ac631cf0c3981e9d0847e4 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:49:55 +0300 Subject: [PATCH 18/30] docs(code): tighten passive voice per style guide --- .../supported-languages-list/swift-and-objective-c.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md index d23fd998ae72..359567b8ae12 100644 --- a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md +++ b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md @@ -82,7 +82,7 @@ For Objective-C, Snyk supports `.m` files, and implicitly supports `.h` files. ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Swift and Objective-C, Snyk Code supports the following template engines: From cfc6d125f2b20f4336da8373e01aebc20d4c7cbd Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:50:17 +0300 Subject: [PATCH 19/30] docs(code): tighten passive voice per style guide --- .../supported-languages/supported-languages-list/typescript.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/typescript.md b/discover-snyk/supported-languages/supported-languages-list/typescript.md index 2ae1bf756202..3a87aaa4d3c9 100644 --- a/discover-snyk/supported-languages/supported-languages-list/typescript.md +++ b/discover-snyk/supported-languages/supported-languages-list/typescript.md @@ -48,7 +48,7 @@ Available features: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For TypeScript, Snyk Code supports the following template engines: From 452959906860db43b8c2a527e30bf257723b2330 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:51:12 +0300 Subject: [PATCH 20/30] docs(code): tighten passive voice per style guide --- .../java-and-kotlin/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index 279e6f00ccf0..89b6bed075d7 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -116,7 +116,7 @@ Kotlin only: {% endcolumn %} {% endcolumns %} -For SAP Commerce (Hybris), Snyk Code analyzes FlexibleSearch queries for SQL injection. This is supported for Java only. Values supplied through query parameter binding are recognized as safe and are not reported. +For SAP Commerce (Hybris), Snyk Code analyzes FlexibleSearch queries for SQL injection. This is supported for Java only. Snyk Code recognizes values supplied through query parameter binding as safe and does not report them. ### Supported package managers and package registries @@ -142,7 +142,7 @@ Available features: ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Java and Kotlin, Snyk Code supports the following template engines: From 17c894154675348e73a2c7404e4ac67e0f1eab40 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:51:49 +0300 Subject: [PATCH 21/30] docs(code): tighten passive voice per style guide --- .../supported-languages-list/python/README.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index fdf03d802717..559c1a247fc6 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -88,7 +88,7 @@ For Python, the following frameworks and libraries are supported: {% endcolumn %} {% endcolumns %} -Snyk Code treats data returned through LangChain LiteLLM as untrusted, so model output that reaches a sink is reported in the same way as any other untrusted input. +Snyk Code treats data returned through LangChain LiteLLM as untrusted, so it reports model output that reaches a sink the same way it reports any other untrusted input. ### Serverless support @@ -114,7 +114,7 @@ Both `src-layout` and `flat-layout` are supported. Proper adherence to these con ### Template file analysis -Snyk Code parses template files and follows data from your application code into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template renders its output is reported. The reported data flow runs from the application code through to the template. Analysis previously stopped at the template boundary. +Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. For Python, Snyk Code supports the following template engines: From 335c2f237340cccd9b50ea991335865da20b93d6 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:52:28 +0300 Subject: [PATCH 22/30] docs(code): tighten passive voice per style guide --- .../technical-specifications-and-guidance.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index 8b549105042e..1bff6ae4beb8 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -74,9 +74,9 @@ Snyk continuously expands its framework coverage and improves analysis accuracy. ### Template file analysis -Snyk Code analyzes template files together with the application code that renders them. Data that reaches a template from your application code is followed into the template, so a cross-site scripting vulnerability that becomes exploitable only where the template writes its output is reported. The reported data flow spans both the application code and the template. +Snyk Code analyzes template files together with the application code that renders them. Snyk Code follows data that reaches a template from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template writes its output. The reported data flow spans both the application code and the template. -Snyk Code takes the escaping behavior of the template engine into account. Output written through the default escaping of the engine is not reported. Output written through a construct that bypasses escaping, such as a raw or unescaped directive, is treated as a sink. +Snyk Code takes the escaping behavior of the template engine into account. Snyk Code does not report output written through the default escaping of the engine. Snyk Code treats output written through a construct that bypasses escaping, such as a raw or unescaped directive, as a sink. Support is defined by the pairing of a template engine with the language that renders the template. The following pairs are supported. Template files are analyzed in addition to the source file formats listed for each language. From 977c205dce13ea74fce5079a46cb9686e62f9d99 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Fri, 11 Sep 2026 13:57:15 +0300 Subject: [PATCH 23/30] docs(code): tighten passive voice per style guide --- discover-snyk/whats-new.md | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md index 05835308bafe..7dd8352dffa1 100644 --- a/discover-snyk/whats-new.md +++ b/discover-snyk/whats-new.md @@ -15,14 +15,14 @@ The most recent updates include significant changes to the user docs, such as fe * Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Each supported template engine is analyzed in the languages it is supported with. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. * Java analysis now covers Java SE 25. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. -* Java framework and library coverage was added or improved for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. SAP Commerce (Hybris) FlexibleSearch queries are analyzed for SQL injection, with parameter binding recognized as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. +* Snyk added or improved Java framework and library coverage for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. Snyk Code analyzes SAP Commerce (Hybris) FlexibleSearch queries for SQL injection and recognizes parameter binding as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. * LangChain LiteLLM is recognized as a source of untrusted data in Python. Visit [Python](https://docs.snyk.io/supported-languages/supported-languages-list/python) for more details. -* Rule coverage was extended for Java, Kotlin, C#, Go, JavaScript, and PHP, with additional sources, sinks, and unsafe API patterns, in particular for cryptography. Nothing needs to be enabled and no configuration changes. Expect additional findings in code that was already being scanned. Visit [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) for more details. -* From September 14, 2026, `.gitignore` rules exclude only untracked files, matching the behavior of Git itself. Files committed to the repository are analyzed even when a `.gitignore` rule matches them, which increases the number of files in scope and therefore the number of findings. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. +* Snyk extended rule coverage for Java, Kotlin, C#, Go, JavaScript, and PHP, with additional sources, sinks, and unsafe API patterns, in particular for cryptography. Nothing needs to be enabled, and no configuration changes are required. Expect additional findings in code that was already being scanned. Visit [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) for more details. +* From September 14, 2026, `.gitignore` rules exclude only untracked files, matching the behavior of Git itself. Snyk analyzes files committed to the repository even when a `.gitignore` rule matches them, which increases the number of files in scope and therefore the number of findings. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. ### Snyk Secrets -* From September 14, 2026, secrets are detected in files committed to the repository even when a `.gitignore` rule matches them. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. +* From September 14, 2026, Snyk detects secrets in files committed to the repository even when a `.gitignore` rule matches them. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. ## August 2026 From 5110c4a4ed19906c9acda6690f376b716bfa5a13 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Fri, 11 Sep 2026 13:23:54 +0100 Subject: [PATCH 24/30] docs(code): add HTTP response splitting and X-Frame-Options to Python rules, XPath injection to Rust --- .../snyk-code/snyk-code-security-rules/python-rules.md | 2 ++ .../snyk-code/snyk-code-security-rules/rust-rules.md | 1 + 2 files changed, 3 insertions(+) diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md index 7ac6571207b9..e72b45a7ed90 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/python-rules.md @@ -24,6 +24,7 @@ Each rule includes the following information. | Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 | | Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 | | Hardcoded Secret | CWE-547 | OWASP:A02:2025 | +| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 | | Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 | | Insecure default value | CWE-453 | None | | Insecure File Permissions | CWE-732 | OWASP:A01:2025 | @@ -47,6 +48,7 @@ Each rule includes the following information. | Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 | | Arbitrary File Write via Archive Extraction (Tar Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 | | Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 | +| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 | | Cryptographic Issues | CWE-310 | None | | Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 | | Python 2 source code | CWE-1104 | OWASP:A03:2025 | diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md index f1e19bc7bdb3..3bde3e45581e 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/rust-rules.md @@ -32,3 +32,4 @@ Each rule includes the following information. | Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 | | Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 | | Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 | +| XPath Injection | CWE-643 | OWASP:A05:2025 | From a15968872b15a77ac70681ee1aa9930ce0558dcb Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Fri, 11 Sep 2026 13:32:15 +0100 Subject: [PATCH 25/30] docs(code): correct three COBOL CWE mappings and add the hardcoded credential rules --- .../snyk-code/snyk-code-security-rules/cobol-rules.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md index ea55ba9ea6ec..a5c0c304dcf0 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/cobol-rules.md @@ -14,17 +14,19 @@ Each rule includes the following information. | Rule Name | CWEs | Security Categories | | --------------------------------------------------- | ---------------- | ---------------------------------------------------------------------- | | Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 | -| Use of Hardcoded Cryptographic Initialization Value | CWE-321 | OWASP:A04:2025 | +| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 | | No Dynamic SQL Clauses | CWE-89 | CWE Top 25, OWASP:A05:2025 | | Inadequate Encryption Strength - Small Key Size | CWE-326 | OWASP:A04:2025 | | Weak Cryptographic Primitive | CWE-327 | OWASP:A04:2025 | -| Clear Text Logging | CWE-321 | OWASP:A04:2025 | +| Clear Text Logging | CWE-312 | OWASP:A06:2025 | | Hardcoded Secret | CWE-547 | OWASP:A02:2025 | +| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 | +| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 | | Injection on Accept | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 | | Insecure Debug Features Enabled | CWE-489, CWE-215 | OWASP:A02:2025, OWASP:A10:2025 | | Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 | | SQL SELECT statement without WHERE clause | CWE-668 | OWASP:A01:2025 | | Multiple CICS HANDLE ABEND Declarations | CWE-755 | OWASP:A10:2025 | | Missing SQL Communication Area (SQLCA) | CWE-391 | OWASP:A10:2025 | -| Ignored Error Condition | CWE-391 | OWASP:A10:2025 | +| Ignored Error Condition | CWE-754 | OWASP:A10:2025 | | Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 | From f2133b15e2bc184b08bd60828b9030421a51a3ae Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Mon, 14 Sep 2026 09:28:30 +0100 Subject: [PATCH 26/30] Limit template file analysis docs to the engine-host pairs in the release The release covers 7 host languages and 11 engines. Remove the section from TypeScript, Scala, Ruby, Swift/Objective-C, Go and C/C++, which are not hosts, and correct the extension list: multi-dot extensions cannot match, .mak is a Makefile extension, and Thymeleaf ships .html only. Co-Authored-By: Claude Opus 5 (1M context) --- .../java-and-kotlin/README.md | 3 --- .../supported-languages-list/.net/README.md | 2 +- .../supported-languages-list/c-c++.md | 10 ---------- .../supported-languages-list/go.md | 10 ---------- .../supported-languages-list/php.md | 2 -- .../supported-languages-list/python/README.md | 1 - .../supported-languages-list/ruby.md | 10 ---------- .../supported-languages-list/scala.md | 15 -------------- .../swift-and-objective-c.md | 10 ---------- .../supported-languages-list/typescript.md | 13 ------------ .../technical-specifications-and-guidance.md | 20 +++++++++---------- 11 files changed, 11 insertions(+), 85 deletions(-) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index 89b6bed075d7..7772701352d8 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -147,9 +147,6 @@ Snyk Code parses template files and follows data from your application code into For Java and Kotlin, Snyk Code supports the following template engines: * FreeMarker -* Handlebars -* Mustache -* Pug * Thymeleaf * Velocity diff --git a/discover-snyk/supported-languages/supported-languages-list/.net/README.md b/discover-snyk/supported-languages/supported-languages-list/.net/README.md index ffcf39cb567e..367a91d87f5e 100644 --- a/discover-snyk/supported-languages/supported-languages-list/.net/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/.net/README.md @@ -48,7 +48,7 @@ For .NET with Snyk Code, the following frameworks and libraries are supported: Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. -For C# and VB.NET, Snyk Code supports the following template engines: +For C#, Snyk Code supports the following template engines: * Mustache * Razor diff --git a/discover-snyk/supported-languages/supported-languages-list/c-c++.md b/discover-snyk/supported-languages/supported-languages-list/c-c++.md index ac29026615c7..e4d35d668a73 100644 --- a/discover-snyk/supported-languages/supported-languages-list/c-c++.md +++ b/discover-snyk/supported-languages/supported-languages-list/c-c++.md @@ -79,16 +79,6 @@ For C/C++ Projects: When using the IDE, you do not need additional options. The Snyk plugin displays results in the IDE views. -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For C/C++, Snyk Code supports the following template engines: - -* Mustache - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## C/C++ for Snyk Open Source ### Available features diff --git a/discover-snyk/supported-languages/supported-languages-list/go.md b/discover-snyk/supported-languages/supported-languages-list/go.md index 27e15f41357a..09ffe92ce07a 100644 --- a/discover-snyk/supported-languages/supported-languages-list/go.md +++ b/discover-snyk/supported-languages/supported-languages-list/go.md @@ -51,16 +51,6 @@ Available features: * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Go, Snyk Code supports the following template engines: - -* Mustache - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## Go for Snyk Open Source ### Available features diff --git a/discover-snyk/supported-languages/supported-languages-list/php.md b/discover-snyk/supported-languages/supported-languages-list/php.md index 10e713341aa9..86b93443a5e7 100644 --- a/discover-snyk/supported-languages/supported-languages-list/php.md +++ b/discover-snyk/supported-languages/supported-languages-list/php.md @@ -43,8 +43,6 @@ Snyk Code parses template files and follows data from your application code into For PHP, Snyk Code supports the following template engines: -* Mustache -* Pug * Twig For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index 559c1a247fc6..44f1046ffac1 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -120,7 +120,6 @@ For Python, Snyk Code supports the following template engines: * Jinja2 * Mako -* Mustache For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). diff --git a/discover-snyk/supported-languages/supported-languages-list/ruby.md b/discover-snyk/supported-languages/supported-languages-list/ruby.md index 118f5204c1f6..6f60a43d1fca 100644 --- a/discover-snyk/supported-languages/supported-languages-list/ruby.md +++ b/discover-snyk/supported-languages/supported-languages-list/ruby.md @@ -70,16 +70,6 @@ Available features: * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Ruby, Snyk Code supports the following template engines: - -* Mustache - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## Ruby for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/supported-languages-list/scala.md b/discover-snyk/supported-languages/supported-languages-list/scala.md index f95f33c4b78a..0ed0f5f0f8e8 100644 --- a/discover-snyk/supported-languages/supported-languages-list/scala.md +++ b/discover-snyk/supported-languages/supported-languages-list/scala.md @@ -57,21 +57,6 @@ The **Snyk Fix PR** feature is not available for Swift and Objective-C. This mea * "**Fixed in" available** is set to **Yes.** {% endhint %} -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Scala, Snyk Code supports the following template engines: - -* FreeMarker -* Handlebars -* Mustache -* Pug -* Thymeleaf -* Velocity - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## Scala for Snyk Open Source For Scala with Snyk Open Source, the following file format is supported: `build.sbt` diff --git a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md index 359567b8ae12..0d0e634f7ca0 100644 --- a/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md +++ b/discover-snyk/supported-languages/supported-languages-list/swift-and-objective-c.md @@ -80,16 +80,6 @@ For Objective-C, Snyk supports `.m` files, and implicitly supports `.h` files. * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Swift and Objective-C, Snyk Code supports the following template engines: - -* Mustache - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## Swift and Objective-C for Snyk Open Source For Swift with Snyk Open Source, Snyk supports Swifts versions from 3.0 up to 6.2.x. diff --git a/discover-snyk/supported-languages/supported-languages-list/typescript.md b/discover-snyk/supported-languages/supported-languages-list/typescript.md index 3a87aaa4d3c9..6359a9c3db74 100644 --- a/discover-snyk/supported-languages/supported-languages-list/typescript.md +++ b/discover-snyk/supported-languages/supported-languages-list/typescript.md @@ -46,19 +46,6 @@ Available features: * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For TypeScript, Snyk Code supports the following template engines: - -* EJS -* Handlebars -* Mustache -* Pug - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## TypeScript for Snyk Open Source For TypeScript with Snyk Open Source, the following file formats are supported: diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index 1bff6ae4beb8..1d785ec46dce 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -82,17 +82,17 @@ Support is defined by the pairing of a template engine with the language that re | Template engine | File extensions | Languages | | :--- | :--- | :--- | -| EJS | `.ejs` | JavaScript, TypeScript | -| FreeMarker | `.ftl`, `.ftlh` | Java, Kotlin, Scala, Groovy | -| Handlebars | `.hbs`, `.handlebars` | JavaScript, TypeScript, Java, Kotlin, Scala | +| EJS | `.ejs` | JavaScript | +| FreeMarker | `.ftl`, `.ftlh`, `.ftlx` | Java, Kotlin, Groovy | +| Handlebars | `.hbs`, `.handlebars` | JavaScript | | Jinja2 | `.j2`, `.jinja`, `.jinja2` | Python | -| Mako | `.mako`, `.mak` | Python | -| Mustache | `.mustache` | JavaScript, TypeScript, Java, Kotlin, Scala, Python, Ruby, PHP, C#, VB.NET, Go, C/C++, Swift, Objective-C | -| Pug | `.pug`, `.jade` | JavaScript, TypeScript, Java, Kotlin, Scala, PHP | -| Razor | `.cshtml`, `.razor`, `.vbhtml` | C#, VB.NET | -| Thymeleaf | `.html`, `.xml` | Java, Kotlin, Scala, Groovy | -| Twig | `.twig`, `.html.twig` | PHP | -| Velocity | `.vm`, `.vtl` | Java, Kotlin, Scala, Groovy | +| Mako | `.mako` | Python | +| Mustache | `.mustache`, `.mu` | JavaScript, C# | +| Pug | `.pug`, `.jade` | JavaScript | +| Razor | `.cshtml`, `.razor` | C# | +| Thymeleaf | `.html` | Java, Kotlin, Groovy | +| Twig | `.twig` | PHP | +| Velocity | `.vm`, `.vtl` | Java, Kotlin, Groovy | Snyk is expanding this coverage. If a template engine or a pair you use is not listed, [contact Snyk Support](https://support.snyk.io). From a3afb8aec761fedd3d7db638fea1f91f450bbee2 Mon Sep 17 00:00:00 2001 From: mihaisau-snyk Date: Mon, 14 Sep 2026 11:36:09 +0300 Subject: [PATCH 27/30] Apply suggestion from @cursor[bot] Co-authored-by: cursor[bot] <206951365+cursor[bot]@users.noreply.github.com> --- scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md index 27fc0893332d..3b58bb5158d8 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md @@ -39,7 +39,7 @@ Snyk Code is powered by a semantic, AI-based analysis engine and can analyze the
Hardcoded secret found

Hardcoded secret found

* Point-to analysis: Identifies multiple potential issues, including buffer overruns, null dereferences, and type mismatches, by modeling memory use in variables and references. -* Template files: Follows data from your application code into the template that renders it, so cross-site scripting that becomes exploitable only at the point of rendering is reported. See [Template file analysis](https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/technical-specifications-and-guidance#template-file-analysis). +* Template files: Follows data from your application code into the template that renders it, so cross-site scripting that becomes exploitable only at the point of rendering is reported. Visit [Template file analysis](../../../discover-snyk/supported-languages/technical-specifications-and-guidance.md#template-file-analysis). * Type inference: Determines the initial type and its changes. This is of special interest for dynamically typed languages. * Value ranges: Infers possible values for variables used to call functions to track off-by-one errors in arrays, division-by-zero errors, and null dereferences. From 10e40962d92b347af17da9a248c36cce52caadcf Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Mon, 14 Sep 2026 13:49:04 +0100 Subject: [PATCH 28/30] docs: drop the September What's new entry, owned by the docs automation Co-Authored-By: Claude Opus 5 (1M context) --- discover-snyk/whats-new.md | 15 --------------- 1 file changed, 15 deletions(-) diff --git a/discover-snyk/whats-new.md b/discover-snyk/whats-new.md index 7dd8352dffa1..5a56542ad25e 100644 --- a/discover-snyk/whats-new.md +++ b/discover-snyk/whats-new.md @@ -9,21 +9,6 @@ nav_context: new The most recent updates include significant changes to the user docs, such as features added or removed, structural changes that affect how you find relevant information, and other improvements to enhance your interaction with the Snyk knowledge base. -## September 2026 - -### Snyk Code - -* Template files are analyzed together with the application code that renders them, so cross-site scripting that becomes exploitable where the template writes its output is reported. Each supported template engine is analyzed in the languages it is supported with. Visit [Template file analysis](https://docs.snyk.io/supported-languages/technical-specifications-and-guidance#template-file-analysis) for more details. -* Java analysis now covers Java SE 25. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. -* Snyk added or improved Java framework and library coverage for Apache CXF including its HTTP transport, OkHttp, Spring Security OAuth2 Client, Google OAuth Client, Google API Client, MSAL4J, Apache Commons Collections, Flyway, and JAXB. Snyk Code analyzes SAP Commerce (Hybris) FlexibleSearch queries for SQL injection and recognizes parameter binding as safe. Visit [Java and Kotlin](https://docs.snyk.io/supported-languages/supported-languages-list/java-and-kotlin) for more details. -* LangChain LiteLLM is recognized as a source of untrusted data in Python. Visit [Python](https://docs.snyk.io/supported-languages/supported-languages-list/python) for more details. -* Snyk extended rule coverage for Java, Kotlin, C#, Go, JavaScript, and PHP, with additional sources, sinks, and unsafe API patterns, in particular for cryptography. Nothing needs to be enabled, and no configuration changes are required. Expect additional findings in code that was already being scanned. Visit [Snyk Code security rules](https://docs.snyk.io/scan-with-snyk/snyk-code/snyk-code-security-rules) for more details. -* From September 14, 2026, `.gitignore` rules exclude only untracked files, matching the behavior of Git itself. Snyk analyzes files committed to the repository even when a `.gitignore` rule matches them, which increases the number of files in scope and therefore the number of findings. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. - -### Snyk Secrets - -* From September 14, 2026, Snyk detects secrets in files committed to the repository even when a `.gitignore` rule matches them. Visit [Snyk Code](https://docs.snyk.io/scan-with-snyk/snyk-code) for more details. - ## August 2026 ### Snyk supported languages From c0b353af98440182e70ac10d61c5194d71b39069 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Mon, 14 Sep 2026 15:50:32 +0100 Subject: [PATCH 29/30] docs(code): move template file analysis out to its own PR for the September 21 release Co-Authored-By: Claude Opus 5 (1M context) --- .../java-and-kotlin/README.md | 12 ---------- .../supported-languages-list/.net/README.md | 11 --------- .../supported-languages-list/groovy.md | 12 ---------- .../javascript/README.md | 13 ---------- .../supported-languages-list/php.md | 10 -------- .../supported-languages-list/python/README.md | 11 --------- .../technical-specifications-and-guidance.md | 24 ------------------- .../scan-with-snyk/snyk-code/README.md | 1 - 8 files changed, 94 deletions(-) diff --git a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md index a784ace6ce43..6293b69a53db 100644 --- a/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md +++ b/discover-snyk/supported-languages-package-managers-and-frameworks/java-and-kotlin/README.md @@ -140,18 +140,6 @@ Available features: * Interfile analysis - Kotlin is fully supported * Interfile analysis - Android is partially supported -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Java and Kotlin, Snyk Code supports the following template engines: - -* FreeMarker -* Thymeleaf -* Velocity - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../supported-languages/technical-specifications-and-guidance.md#template-file-analysis). - ## Java and Kotlin for Snyk Open Source For Java and Kotlin with Snyk Open Source, the following file formats are supported: diff --git a/discover-snyk/supported-languages/supported-languages-list/.net/README.md b/discover-snyk/supported-languages/supported-languages-list/.net/README.md index 011ada882038..b574d4e83882 100644 --- a/discover-snyk/supported-languages/supported-languages-list/.net/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/.net/README.md @@ -46,17 +46,6 @@ For .NET with Snyk Code, the following frameworks and libraries are supported: * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For C#, Snyk Code supports the following template engines: - -* Mustache -* Razor - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). - ## .NET for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/supported-languages-list/groovy.md b/discover-snyk/supported-languages/supported-languages-list/groovy.md index 9601310c6e4a..50d392ab7288 100644 --- a/discover-snyk/supported-languages/supported-languages-list/groovy.md +++ b/discover-snyk/supported-languages/supported-languages-list/groovy.md @@ -40,15 +40,3 @@ For Groovy, Snyk supports the following file extensions: * Support for Interfile analysis * Reports - -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Groovy, Snyk Code supports the following template engines: - -* FreeMarker -* Thymeleaf -* Velocity - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). diff --git a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md index 48944cd46efd..3111960c1a4d 100644 --- a/discover-snyk/supported-languages/supported-languages-list/javascript/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/javascript/README.md @@ -111,19 +111,6 @@ The following file formats are supported: `.ejs`, `.es`, `.es6`, `.htm`, `.html` * Reports * Interfile analysis -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For JavaScript, Snyk Code supports the following template engines: - -* EJS -* Handlebars -* Mustache -* Pug - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). - ## JavaScript for Snyk Open Source ### Supported package managers and package registries diff --git a/discover-snyk/supported-languages/supported-languages-list/php.md b/discover-snyk/supported-languages/supported-languages-list/php.md index 6d22b95472f7..cd1e36a9496d 100644 --- a/discover-snyk/supported-languages/supported-languages-list/php.md +++ b/discover-snyk/supported-languages/supported-languages-list/php.md @@ -39,16 +39,6 @@ For PHP, the following frameworks and libraries are supported: The following file formats are supported: `.php`, `.phtml`, `.module`, `.inc`, `.install`, `.theme`, `.profile`. -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For PHP, Snyk Code supports the following template engines: - -* Twig - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../technical-specifications-and-guidance.md#template-file-analysis). - ## PHP for Snyk Open Source For PHP with Snyk Open Source, PHP versions 5.2 through 8.5 are supported. diff --git a/discover-snyk/supported-languages/supported-languages-list/python/README.md b/discover-snyk/supported-languages/supported-languages-list/python/README.md index 2332b2b2a7e3..31402e7e9481 100644 --- a/discover-snyk/supported-languages/supported-languages-list/python/README.md +++ b/discover-snyk/supported-languages/supported-languages-list/python/README.md @@ -113,17 +113,6 @@ Snyk Code relies on Python projects to follow a standard directory layout for ac Both `src-layout` and `flat-layout` are supported. Proper adherence to these conventions allows the scanner to trace code effectively and provide accurate results. -### Template file analysis - -Snyk Code parses template files and follows data from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template renders its output. - -For Python, Snyk Code supports the following template engines: - -* Jinja2 -* Mako - -For file extensions and the full set of supported language and template engine combinations, visit [Template file analysis](../../technical-specifications-and-guidance.md#template-file-analysis). - ## Python for Snyk Open Source {% hint style="info" %} diff --git a/discover-snyk/supported-languages/technical-specifications-and-guidance.md b/discover-snyk/supported-languages/technical-specifications-and-guidance.md index f0480ca485c8..7694639a99be 100644 --- a/discover-snyk/supported-languages/technical-specifications-and-guidance.md +++ b/discover-snyk/supported-languages/technical-specifications-and-guidance.md @@ -74,30 +74,6 @@ Partial support includes: Snyk continuously expands its framework coverage and improves analysis accuracy. -### Template file analysis - -Snyk Code analyzes template files together with the application code that renders them. Snyk Code follows data that reaches a template from your application code into the template, so it reports a cross-site scripting vulnerability that becomes exploitable only where the template writes its output. The reported data flow spans both the application code and the template. - -Snyk Code takes the escaping behavior of the template engine into account. Snyk Code does not report output written through the default escaping of the engine. Snyk Code treats output written through a construct that bypasses escaping, such as a raw or unescaped directive, as a sink. - -Support is defined by the pairing of a template engine with the language that renders the template. The following pairs are supported. Template files are analyzed in addition to the source file formats listed for each language. - -| Template engine | File extensions | Languages | -| :--- | :--- | :--- | -| EJS | `.ejs` | JavaScript | -| FreeMarker | `.ftl`, `.ftlh`, `.ftlx` | Java, Kotlin, Groovy | -| Handlebars | `.hbs`, `.handlebars` | JavaScript | -| Jinja2 | `.j2`, `.jinja`, `.jinja2` | Python | -| Mako | `.mako` | Python | -| Mustache | `.mustache`, `.mu` | JavaScript, C# | -| Pug | `.pug`, `.jade` | JavaScript | -| Razor | `.cshtml`, `.razor` | C# | -| Thymeleaf | `.html` | Java, Kotlin, Groovy | -| Twig | `.twig` | PHP | -| Velocity | `.vm`, `.vtl` | Java, Kotlin, Groovy | - -Snyk is expanding this coverage. If a template engine or a pair you use is not listed, [contact Snyk Support](https://support.snyk.io). - ### How Snyk Code analysis works Snyk scans your codebase following this sequence: diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md index 3b58bb5158d8..f082f11eac12 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md @@ -39,7 +39,6 @@ Snyk Code is powered by a semantic, AI-based analysis engine and can analyze the
Hardcoded secret found

Hardcoded secret found

* Point-to analysis: Identifies multiple potential issues, including buffer overruns, null dereferences, and type mismatches, by modeling memory use in variables and references. -* Template files: Follows data from your application code into the template that renders it, so cross-site scripting that becomes exploitable only at the point of rendering is reported. Visit [Template file analysis](../../../discover-snyk/supported-languages/technical-specifications-and-guidance.md#template-file-analysis). * Type inference: Determines the initial type and its changes. This is of special interest for dynamically typed languages. * Value ranges: Infers possible values for variables used to call functions to track off-by-one errors in arrays, division-by-zero errors, and null dereferences. From 8366f4443babf6c77acc3252d57dc7c09c2e3c28 Mon Sep 17 00:00:00 2001 From: Sebastian Roth Date: Mon, 14 Sep 2026 18:06:38 +0100 Subject: [PATCH 30/30] docs(code): add the HSTS Disabled rule to the Ruby and Java rule tables Co-Authored-By: Claude Opus 5 (1M context) --- .../snyk-code/snyk-code-security-rules/java-rules.md | 1 + .../snyk-code/snyk-code-security-rules/ruby-rules.md | 1 + 2 files changed, 2 insertions(+) diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md index c74a82b3be5a..ada898624dc4 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/java-rules.md @@ -29,6 +29,7 @@ Each rule includes the following information. | Android Fragment Injection | CWE-470 | OWASP:A05:2025 | | Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 | | Hardcoded Secret | CWE-547 | OWASP:A02:2025 | +| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 | | Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 | | Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 | | Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 | diff --git a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md index 7dc58d49d887..d49f28c49bc9 100644 --- a/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md +++ b/scan-fix-and-prevent/scan-with-snyk/snyk-code/snyk-code-security-rules/ruby-rules.md @@ -21,6 +21,7 @@ Each rule includes the following information. | Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 | | Hardcoded Secret | CWE-547 | OWASP:A02:2025 | | Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 | +| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 | | Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 | | Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 | | Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |