Skip to content

Implement Snyk security provider scans - #167

Closed
Robertg761 wants to merge 1 commit into
profullstack:masterfrom
Robertg761:codex/security-snyk-cli
Closed

Robertg761 wants to merge 1 commit into
profullstack:masterfrom
Robertg761:codex/security-snyk-cli

Conversation

@Robertg761

Copy link
Copy Markdown

Related to #6 and #133.

This upgrades the security-snyk adapter from log-only scan stubs to real Snyk CLI-backed security scans.

What changed:

  • require SNYK_TOKEN (or configurable tokenKey) from the vault before connect/scan operations
  • verify auth during connect with snyk auth <token> and snyk whoami
  • run dependency, container, and IaC scans through the correct Snyk command families with --json
  • parse Snyk JSON output into sh1pt SecurityFinding[] values
  • pass org/token context into the CLI environment and return a clear install hint if snyk is missing
  • add mocked-CLI tests for dependency/container/IaC scans, connect, and missing-token behavior

Verified:

  • pnpm exec vitest run packages/security/snyk/src/index.test.ts
  • pnpm --filter @profullstack/sh1pt-security-snyk typecheck
  • pnpm --filter @profullstack/sh1pt typecheck
  • git diff --check

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant