1.1308.0 (2026-10-08)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
- test, code, secrets:
snyk test,snyk code testandsnyk secrets testcan now generate an HTML report. Use--htmlto print it to stdout, or--html-file-output=<path>to write it to a file. (0e10434, af6a2a4) - agent-scan: The experimental
snyk agent-scancommand now reports risk indicators instead of issue codes. If you post-process its--jsonoutput, update your scripts to the new format. (d5451a6)
Bug Fixes
- sbom: Maven and Gradle SBOMs, and
--print-graph, no longer stall on large multi-module builds. They now finish seconds after the build tool exits. On projects with dependency cycles, the output may contain extrapruned: cyclicplaceholder nodes. No packages or dependency edges are dropped. (73f038c) - test: Gradle projects with very deep inter-module dependency chains no longer fail with a stack overflow. (fc4f8ec, ce4e5d6)
- test: .NET scans fall back to legacy scanning when the .NET SDK isn't installed. They also handle projects restored in a different build directory, and work when global NuGet source-mapping rules are configured. (b8461c8)
- test: .NET scans no longer fail with
NU1101on SDK installs that lack the app host pack, such as distro-packaged SDKs. (1fd1fa4) - test: .NET projects whose
PackageReferenceuses a lowercaseversionattribute are now parsed correctly. (108f8ca) - test: Projects built with Gradle 4.0 to 4.6 no longer fail to scan. (1070653)
- deps: Updates dependencies to fix vulnerabilities: