Snyk helps you find, fix and monitor for known vulnerabilities in your dependencies, both on an ad hoc basis and as part of your CI (Build) system. Snyk Composer Lockfile Parser Given a composer.json & composer.lock builds a dep tree