For the complete documentation index, see llms.txt. This page is also available as Markdown.

Configure Snyk ingestion

Connect Snyk to Cortex Cloud, select findings, and manage the integration.

Connect Snyk to Cortex Cloud to ingest SCA and SAST findings.

Prerequisites

Complete the Snyk prerequisites before onboarding.

Onboarding steps

  1. Navigate to SettingsData Sources & Integrations+ Add New.

  2. Search for and hover over Snyk and click Add, or Add Another Instance if an instance is already onboarded.

  3. On the Configure Integration step of the integration wizard.

    1. Configure Snyk parameters:

      • Select your Snyk API URL from the menu (for example API URLSNYK-US-02 (https://api.us.snyk.io/rest))

      • Enter your Snyk API token

    2. Click Authorize.

  4. On the Select Organization step of the wizard: Enter your Snyk Organization IDNext.

    Note

    Select Test Connection to verify that Cortex Cloud can connect to your Snyk organization.

  5. On the Select Issue Types step of the wizard: Select the type of data findings to be ingested: SAST, SCA or bothNext.

    Note

    • SCA requires Snyk Open Source or Snyk Container projects configured in the organization

    • SAST requires Snyk Code enabled and projects configured in the organization

  6. Select ingestion targets: On the Map to Repositories step of the wizard, review the detected Snyk projects and confirm or manage their repository mappings

      • Select Automatically map future Snyk applications to automatically map current and future Snyk projects to Cortex Cloud repositories. This is recommended to ensure maximum security coverage

      • Configure unmapped or mismatched applications: Manually configure mapping if Cortex Cloud cannot match an application to a repository or an update to the mapping is required: From the list of detected applications, select the application from the list, then choose the correct repository from the Repository dropdown menu

    1. Click Save.

    Note

    • Mapping establishes relationships between Snyk applications and Cortex Cloud code repositories, simplifying access management and enabling risk analysis at the repository level, including displaying findings on the tenant

    • Only mapped applications are ingested

    After saving, Cortex Cloud triggers the initial scan ingestion for the selected targets.

Verify integration

Verify the integration in Cortex Cloud:

  • On Data Sources & Integrations, filter for Snyk. Select the data source and confirm your instance and mapped applications show Connected.

Last updated

Was this helpful?