Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
aa0e5bf
docs(code): .gitignore excludes only untracked files from September 14
sebsnyk Aug 20, 2026
066a577
docs(code): document template file analysis for cross-site scripting
sebsnyk Aug 20, 2026
6c1b3e8
docs(code): Java analysis supports Java SE 25
sebsnyk Aug 20, 2026
f3f8265
docs(code): add Java framework and library coverage, including Hybris…
sebsnyk Aug 20, 2026
c281b6b
docs(code): LangChain LiteLLM is an untrusted data source for Python
sebsnyk Aug 20, 2026
57ca7c1
docs: add September 2026 Snyk Code and Snyk Secrets updates to What's…
sebsnyk Aug 20, 2026
71b2de3
docs(code): template file analysis covers every language and template…
sebsnyk Sep 8, 2026
011066a
docs(code): document the supported template engine and language pairs
sebsnyk Sep 8, 2026
44e5ca5
docs(code): add Mako to the Python template engine pairs
sebsnyk Sep 10, 2026
cd8163b
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
a9a0a22
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
0eeb389
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
69b5b93
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
cf4f01e
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
bc6cd76
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
30c1c54
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
e0ef0c8
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
7920fa9
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
cfc6d12
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
4529599
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
17c8941
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
335c2f2
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
977c205
docs(code): tighten passive voice per style guide
mihaisau-snyk Sep 11, 2026
5110c4a
docs(code): add HTTP response splitting and X-Frame-Options to Python…
sebsnyk Sep 11, 2026
a159688
docs(code): correct three COBOL CWE mappings and add the hardcoded cr…
sebsnyk Sep 11, 2026
f2133b1
Limit template file analysis docs to the engine-host pairs in the rel…
sebsnyk Sep 14, 2026
a3afb8a
Apply suggestion from @cursor[bot]
mihaisau-snyk Sep 14, 2026
10e4096
docs: drop the September What's new entry, owned by the docs automation
sebsnyk Sep 14, 2026
ba9fb36
Merge remote-tracking branch 'origin/main' into docs/code-september-2…
sebsnyk Sep 14, 2026
c0b353a
docs(code): move template file analysis out to its own PR for the Sep…
sebsnyk Sep 14, 2026
8366f44
docs(code): add the HSTS Disabled rule to the Ruby and Java rule tables
sebsnyk Sep 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ Improved Gradle SCM scanning is in Early Access. For more information, see [SCM

## Technical specifications

Snyk supports Java analysis for Java versions up to SE 21 and is designed to process code from newer Java versions where feasible.
Snyk supports Java analysis for Java versions up to SE 25 and is designed to process code from newer Java versions where feasible.

### Supported frameworks and libraries

Expand All @@ -38,6 +38,8 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Android Standard Library
* Apache Camel
* Apache Commons
* Apache Commons Collections
* Apache CXF
* Apache Tomcat
* Apache XML
* apache.mahou
Expand All @@ -50,7 +52,10 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Dropwizard
* elasticsearch
* FasterXML Jackson
* Flyway
* Google API Client
* Google Guava
* Google OAuth Client
* grpc-java
* hibernate
* http4k
Expand All @@ -64,6 +69,7 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Java Standard Edition
* javalin
* Jax-RS
* JAXB
* Jolokia
* jooq
{% endcolumn %}
Expand All @@ -72,6 +78,7 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* Kyro
* Micronaut
* mongo-java-driver
* MSAL4J
* Netty
* okhttp3
* org.apache.hc.client5
Expand All @@ -82,12 +89,14 @@ For Java and Kotlin, the following frameworks and libraries are supported:
* org.dom4j.io
* Playframework
* rxhttp
* SAP Commerce (Hybris)
* Seam logger
* SnakeYaml
* Spongycastle
* Spring AI
* Spring boot
* Spring Cloud Config
* Spring Security OAuth2 Client
* Spring Web, MVC and JDBC
* Spring WebFlux
* Struts
Expand All @@ -107,6 +116,8 @@ Kotlin only:
{% endcolumn %}
{% endcolumns %}

For SAP Commerce (Hybris), Snyk Code analyzes FlexibleSearch queries for SQL injection. This is supported for Java only. Snyk Code recognizes values supplied through query parameter binding as safe and does not report them.

### Supported package managers and package registries <a href="#supported-package-managers-and-package-registries" id="supported-package-managers-and-package-registries"></a>

* Supported package managers: [Maven](https://maven.apache.org) and [Gradle](https://gradle.org), with the following supported versions:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ For Python, the following frameworks and libraries are supported:
* huggingface\_hub
* iopg
* LangChain
* LangChain LiteLLM
* ldap3
* libxml
* lxml
Expand Down Expand Up @@ -88,6 +89,8 @@ For Python, the following frameworks and libraries are supported:
{% endcolumn %}
{% endcolumns %}

Snyk Code treats data returned through LangChain LiteLLM as untrusted, so it reports model output that reaches a sink the same way it reports any other untrusted input.

### Serverless support

Snyk Code analyzes Python functions that run on AWS Lambda. Snyk resolves handlers from AWS SAM and Serverless Framework configuration files, so it analyzes the function entry point as application code instead of skipping it.
Expand Down
2 changes: 1 addition & 1 deletion scan-fix-and-prevent/scan-with-snyk/snyk-code/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Snyk Code is a developer-first static application security testing (SAST) soluti

The following table shows the Snyk Code features, including analysis, managing security issues in your code, and facilitating remediations within your development environment.

<table><thead><tr><th width="179">Feature</th><th>Description</th></tr></thead><tbody><tr><td>Issue filtering, sorting, and grouping</td><td><p>To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria.</p><p>See <a href="manage-code-vulnerabilities/#filtering-existing-projects">Filter existing Projects</a>.</p></td></tr><tr><td>Priority Score</td><td><p>Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score.</p><p>See <a href="../../manage-risk/prioritize-issues-for-fixing/priority-score.md">Priority score</a>.</p></td></tr><tr><td>Data flow</td><td><p>Visualize the path of the issue from source to sink with a step-by-step flow.</p><p>See <a href="manage-code-vulnerabilities/breakdown-of-code-analysis.md">Data flow</a>.</p></td></tr><tr><td>Vulnerability</td><td><p>Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it.</p><p>See <a href="manage-code-vulnerabilities/">Manage code vulnerabilities</a></p></td></tr><tr><td>Fix analysis</td><td><p>Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows.</p><p>See <a href="manage-code-vulnerabilities/breakdown-of-code-analysis.md">Breakdown of Code analysis</a>.</p></td></tr><tr><td>Create Jira issue</td><td><p>Track and export Snyk issues to your Jira project.</p><p>See <a href="https://app.gitbook.com/s/IEEjSXQQu36y0vmFV8zf/integrations/jira-and-slack-integrations/jira-integration#create-a-jira-issue">Create a Jira issue</a>.</p></td></tr><tr><td>Ignore issues</td><td><p>Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it.</p><p>See <a href="../../manage-risk/prioritize-issues-for-fixing/ignore-issues/">Ignore issues</a>.</p></td></tr><tr><td>Exclude files from the import process</td><td><p>Check for <code>DeepCode/Snyk</code> ignore files <code>.gitignore</code> <code>.dcignore</code> and read them if they exist. Using the information in these files, Snyk filters to identify only the files with <a href="https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/supported-languages-package-managers-and-frameworks">the supported extensions</a> in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk. <code>,gitignore</code> exclusions are honored by the <code>snyk code test</code> CLI command.</p><p>See also <a href="../import-project-repository/exclude-directories-and-files-from-project-import.md">Exclude directories and files from the import process</a>.</p></td></tr><tr><td>Interfile analysis</td><td>This is available for <a href="https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/supported-languages-package-managers-and-frameworks#code-analysis-snyk-code">all languages supported by Snyk Code</a> except Ruby.</td></tr></tbody></table>
<table><thead><tr><th width="179">Feature</th><th>Description</th></tr></thead><tbody><tr><td>Issue filtering, sorting, and grouping</td><td><p>To identify the most common problems, you can filter issues based on their severity, programming language, priority score, and other criteria.</p><p>See <a href="manage-code-vulnerabilities/#filtering-existing-projects">Filter existing Projects</a>.</p></td></tr><tr><td>Priority Score</td><td><p>Sort by and prioritize the more important issues by incorporating factors such as issue prevalence, ease of fix, and risk factor into a single risk score.</p><p>See <a href="../../manage-risk/prioritize-issues-for-fixing/priority-score.md">Priority score</a>.</p></td></tr><tr><td>Data flow</td><td><p>Visualize the path of the issue from source to sink with a step-by-step flow.</p><p>See <a href="manage-code-vulnerabilities/breakdown-of-code-analysis.md">Data flow</a>.</p></td></tr><tr><td>Vulnerability</td><td><p>Learn more about the vulnerability through curated content that explains how the vulnerability was created, what the risk factors are, and popular mitigation strategies for it.</p><p>See <a href="manage-code-vulnerabilities/">Manage code vulnerabilities</a></p></td></tr><tr><td>Fix analysis</td><td><p>Gain insight and context by examining examples with links to actual code that fixes the same issues in similar data flows.</p><p>See <a href="manage-code-vulnerabilities/breakdown-of-code-analysis.md">Breakdown of Code analysis</a>.</p></td></tr><tr><td>Create Jira issue</td><td><p>Track and export Snyk issues to your Jira project.</p><p>See <a href="https://app.gitbook.com/s/IEEjSXQQu36y0vmFV8zf/integrations/jira-and-slack-integrations/jira-integration#create-a-jira-issue">Create a Jira issue</a>.</p></td></tr><tr><td>Ignore issues</td><td><p>Configure Snyk to ignore suggested fixes for an issue to suppress specific warnings. For example, you may have deliberately used hard-coded passwords to test your routines in test code, or you are aware of an issue but have decided not to fix it.</p><p>See <a href="../../manage-risk/prioritize-issues-for-fixing/ignore-issues/">Ignore issues</a>.</p></td></tr><tr><td>Exclude files from the import process</td><td><p>Check for <code>DeepCode/Snyk</code> ignore files <code>.gitignore</code> <code>.dcignore</code> and read them if they exist. Using the information in these files, Snyk filters to identify only the files with <a href="https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/supported-languages-package-managers-and-frameworks">the supported extensions</a> in the Project directory and not above the current Project directory. Snyk Code bundles these files that are smaller than 4 MB and sends them to Snyk.</p><p>From September 14, 2026, <code>.gitignore</code> rules exclude only files that are untracked, matching the behavior of Git itself. Files committed to the repository are analyzed even when a <code>.gitignore</code> rule matches them. This applies to Snyk Code and Snyk Secrets across all interfaces and cannot be disabled. To get this behavior in CLI scans, upgrade to Snyk CLI 1.1307.0 or later. Use <code>.snyk</code> exclude patterns to deliberately exclude a path.</p><p>See also <a href="../import-project-repository/exclude-directories-and-files-from-project-import.md">Exclude directories and files from the import process</a>.</p></td></tr><tr><td>Interfile analysis</td><td>This is available for <a href="https://app.gitbook.com/s/L7HyJj9FsK1W4pNt8Gzl/supported-languages/supported-languages-package-managers-and-frameworks#code-analysis-snyk-code">all languages supported by Snyk Code</a> except Ruby.</td></tr></tbody></table>

## Deployment

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,17 +14,19 @@ Each rule includes the following information.
| Rule Name | CWEs | Security Categories |
| --------------------------------------------------- | ---------------- | ---------------------------------------------------------------------- |
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
| Use of Hardcoded Cryptographic Initialization Value | CWE-321 | OWASP:A04:2025 |
| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 |
| No Dynamic SQL Clauses | CWE-89 | CWE Top 25, OWASP:A05:2025 |
| Inadequate Encryption Strength - Small Key Size | CWE-326 | OWASP:A04:2025 |
| Weak Cryptographic Primitive | CWE-327 | OWASP:A04:2025 |
| Clear Text Logging | CWE-321 | OWASP:A04:2025 |
| Clear Text Logging | CWE-312 | OWASP:A06:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
| Use of Hardcoded Credentials | CWE-798 | OWASP:A07:2025 |
| Injection on Accept | CWE-20 | CWE Top 25, OWASP:A05:2025, OWASP-API:API10:2023, OWASP-Mobile:M4:2024 |
| Insecure Debug Features Enabled | CWE-489, CWE-215 | OWASP:A02:2025, OWASP:A10:2025 |
| Insecure Data Transmission | CWE-319 | OWASP:A04:2025, OWASP-API:API8:2023, OWASP-API:API10:2023 |
| SQL SELECT statement without WHERE clause | CWE-668 | OWASP:A01:2025 |
| Multiple CICS HANDLE ABEND Declarations | CWE-755 | OWASP:A10:2025 |
| Missing SQL Communication Area (SQLCA) | CWE-391 | OWASP:A10:2025 |
| Ignored Error Condition | CWE-391 | OWASP:A10:2025 |
| Ignored Error Condition | CWE-754 | OWASP:A10:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,7 @@ Each rule includes the following information.
| Android Fragment Injection | CWE-470 | OWASP:A05:2025 |
| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 |
| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Disabled Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Inadequate Padding for AES encryption | CWE-326 | OWASP:A04:2025 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ Each rule includes the following information.
| Use of Hardcoded Cryptographic Initialization Value | CWE-329 | OWASP:A04:2025 |
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
| Improper Neutralization of CRLF Sequences in HTTP Headers | CWE-113 | OWASP:A05:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
| Insecure default value | CWE-453 | None |
| Insecure File Permissions | CWE-732 | OWASP:A01:2025 |
Expand All @@ -47,6 +48,7 @@ Each rule includes the following information.
| Inadequate Encryption Strength | CWE-326 | OWASP:A04:2025 |
| Arbitrary File Write via Archive Extraction (Tar Slip) | CWE-22 | CWE Top 25, OWASP:A01:2025 |
| Origin Validation Error | CWE-942, CWE-346 | OWASP:A02:2025, OWASP:A07:2025, OWASP-API:API8:2023 |
| Improper Restriction of Rendered UI Layers or Frames | CWE-1021 | OWASP:A06:2025 |
| Cryptographic Issues | CWE-310 | None |
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
| Python 2 source code | CWE-1104 | OWASP:A03:2025 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ Each rule includes the following information.
| Use of Hardcoded Cryptographic Key | CWE-321 | OWASP:A04:2025 |
| Hardcoded Secret | CWE-547 | OWASP:A02:2025 |
| Use of Hardcoded Passwords | CWE-798, CWE-259 | OWASP:A07:2025 |
| HTTP Strict Transport Security (HSTS) Disabled | CWE-693 | OWASP:A06:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -32,3 +32,4 @@ Each rule includes the following information.
| Use of Insufficiently Random Values | CWE-330 | OWASP:A04:2025 |
| Use of Password Hash With Insufficient Computational Effort | CWE-916 | OWASP:A04:2025 |
| Use of a Broken or Risky Cryptographic Algorithm | CWE-327 | OWASP:A04:2025 |
| XPath Injection | CWE-643 | OWASP:A05:2025 |
Loading