Snyk is a security platform that allows team sto find and fix vulnerabilities in their code. You can use Snyk to drive insights into values such as:
In order to connect Cortex to your Snyk instance, you’ll need to create a Snyk API Token, and add it under Settings → Snyk.
If you do not see the Settings page you're looking for in the sidebar, you likely don't have the proper permissions and need to contact your admin.
Cortex uses the Git repository configured in the Catalog Descriptor to automatically discover the associated Snyk projects. It does so by getting a list of all Snyk projects across all Snyk organizations, and finding any projects that are associated with the same repository.
If you need to override the automatic discovery, you can define the following block in your Cortex Catalog Descriptor.
x-cortex-snyk: projects: - organization: 01234567-e65f-4b7b-a8b1-5b642894ec37 # optionally, we also support the organization slug in this same field projectId: 01234567-e65f-4b7b-a8b1-5b642894ec37
The value for
projectId should be the organizationId (or organizationSlug) and projectId respectively, as defined in Snyk.