Snyk Dependency Audit Skill
Uses the Snyk CLI and REST API v1 to scan package manifests for known CVEs. Cross-references findings with the GitHub Advisory Database and produces SBOM documents in CycloneDX format.
Installation
Requirements and caveats from upstream:
- To use the CLI, you must install it and authenticate your machine. See Install or update the Snyk CLI and [Authenticate the CLI with your account](https:...
- Before you can use the CLI for Open Source scanning, you must install your package manager. The needed third-party tools, such as Gradle or Maven, must be in the PATH.
- Before using the Snyk CLI to test your Open Source Project for vulnerabilities, with limited exceptions, you must build your Project. For details, see [Open Source Projects that must be built before testing](https://d...
Basic usage or getting-started notes:
Introduction to the Snyk CLI
Snyk is a developer-first, cloud-native security tool to scan and monitor your software development projects for security vulnerabilities. Snyk scans multiple content types for security issues:
Snyk Open Source: Find and automatically fix open-source vulnerabilities
Source: https://github.com/snyk/cli
Extracted from upstream docs: https://raw.githubusercontent.com/snyk/cli/HEAD/README.md