Improved Event Currencies & Event Firewall Set event currencies from your dashboard, with a site default and wildcards, and block or allow events from the Firewall. August 25, 2026 Firewall Allow & Block Listsabout 2 months ago
Container: Go standard library vulnerability reporting General availability Snyk Container will begin reporting vulnerabilities from the Go standard library for all customers. Scans of container images built from Go binaries identify the standard library version the binary was compiled with and report known vulnerabilities against it. Affected images gain a new stdlib dependency in the dependency graph, versioned to the Go release used for the build, for example stdlib@1.25.10. Detection works for standard, stripped, and CGo builds. No configuration is required, and reporting is enabled automatically for all organizations. Standard library reporting in the Snyk CLI requires v1.1303.2 or later. This change is scheduled to take effect on October 7, 2026. Snyk Container reported vulnerabilities in third-party Go dependencies, but not in the Go standard library itself, the HTTP, TLS, JSON, and other libraries that ship with the Go toolchain rather than being installed as dependencies. Those vulnerabilities were visible only indirectly, through distro advisories, so teams shipping Go binaries in containers had no reliable way to see them. That left two gaps: one between what Snyk Container reported and what Snyk Open Source already reported for the same code, and one in real coverage for any Go application running in a container - this change closes both. If you scan container images built from Go binaries, your vulnerability counts will increase. Each affected project gains a fixed number of new findings, determined by the Go version the binary was built with. Older Go releases carry more. Building with a current Go patch release substantially reduces or eliminates these findings. Images built with Go 1.25.13 or later, or Go 1.26.6 or later, report no new vulnerabilities from this change. We recommend reviewing the Go versions used in your build pipelines ahead of the release date. Considerations and known limitations: Snyk does not perform reachability analysis on standard library packages. Snyk reports all known vulnerabilities for the standard library version in your binary, rather than only those in packages your code imports. This is consistent with the approach taken by other container scanners. Findings that are not relevant to your application can be ignored in Snyk as usual For more information, see Application vulnerabilities in Snyk Container and Snyk Open Source in the Snyk user documentation: https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-container/how-snyk-container-works/application-vulnerabilities-in-snyk-container-and-snyk-open-source Tags: container cli scm-import September 16, 2026 Custom CA Certificate Support4 days ago
ADS installer now available as a packaged binary Improved The ADS installer now ships as a signed macOS .pkg and Windows .msi, downloaded from the Settings page. The installer registers a scheduled job on the machine, so Agent Supply Chain Security scans run on their own schedule without needing MDM. What The ADS installer now ships as a signed macOS .pkg and Windows .msi, downloaded from the Settings page in Evo. Why Deployment no longer means wrapping a downloaded file in your own script, you now get a standard signed installer for macOS or Windows. The installer now stays on the machine in a predictable location. Scan timing is no longer tied to your MDM policy. How In Evo, open Settings, choose your products and select Save & Publish. Choose your operating system and architecture, select Download ADS Installer, install the package, then run the installer with your Tenant ID and push key. Your onboarding workflow, MDM policies, tenant and push key are all unchanged. Downloading the installer directly from the CDN remains available. Things to know Linux is unchanged. The command line install remains supported and is documented alongside the package flow. For more information, see the documentation: https://docs.snyk.io/agent-security/evo-by-snyk/agentic-development-security-ads Nina Kanti | Senior Product Manager Tags: snyk-studio September 23, 2026 Announcing Snyk CLI v1.1307.418 days ago
Evo MCP Server now available General availability You can connect any MCP client, such as Claude, Codex or Cursor, to Evo and ask about your AI estate from the agent you already work in. What's new. You can now: Ask what AI assets Evo has discovered across your code, your developer machines, and your pentest targets See how those assets connect, for example which MCP servers an agent uses or which findings came from a target Read your policies and the violations open against them Create and update policies without leaving your agent To get started, check out our documentation Nina Kanti | Senior Product Manager Tags: mcp September 18, 2026 Announcing Snyk CLI v1.1307.323 days ago