Code Monkey home page Code Monkey logo

vscode-snyk's Introduction

vscode-snyk

Unofficial Visual Studio Code extension for Snyk.io


DEPRECATION NOTICE

⚠️ This project is now deprecated. As an alternative, I recommend Snyk's official extension: Vuln Cost.

Check your Node.JS and Ruby dependencies against Snyk.io vulnerability database.


feature X

Note: This extension requires internet access to https://snyk.io/vuln/ and will not currently work offline.

Demo

vscode-snyk demo

Usage

This extension adds the Snyk Test command to check your package.json, npm-shrinkwrap, or Gemfile against the Snyk.io VulnDB inventory of known vulnerabilities.

In the command palette (CMD + SHIFT + P), type Snyk Test.

Features

  • If vulnerabilities are found, display an error with a count of vulnerable dependencies vuln count
  • If no vulnerabilities are found, display an info message no vulns
  • Detailed summary of vulnerable dependencies vuln details
  • Hyperlinked URLs directly to Snyk.io VulnDB for more information on remediation.

Release Notes

See CHANGELOG.md.

For more information

vscode-snyk's People

Contributors

pbnj avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

vscode-snyk's Issues

Action required: Greenkeeper could not be activated 🚨

🚨 You need to enable Continuous Integration on all branches of this repository. 🚨

To enable Greenkeeper, you need to make sure that a commit status is reported on all branches. This is required by Greenkeeper because it uses your CI build statuses to figure out when to notify you about breaking changes.

Since we didn’t receive a CI status on the greenkeeper/initial branch, it’s possible that you don’t have CI set up yet. We recommend using Travis CI, but Greenkeeper will work with every other CI service as well.

If you have already set up a CI for this repository, you might need to check how it’s configured. Make sure it is set to run on all new branches. If you don’t want it to run on absolutely every branch, you can whitelist branches starting with greenkeeper/.

Once you have installed and configured CI on this repository correctly, you’ll need to re-trigger Greenkeeper’s initial pull request. To do this, please delete the greenkeeper/initial branch in this repository, and then remove and re-add this repository to the Greenkeeper App’s white list on Github. You'll find this list on your repo or organization’s settings page, under Installed GitHub Apps.

VSCode 1.43.2

Hello!
Forgive me if I am not using the extension correctly but I cannot seem to get it to work on 1.43.2 which is the latest version as of 31/03/2020.

I am able to install the plugin and run 'Snyk Test' however there does not appear to be any output or indication that the scan has run/is running.

Here is the output from the Extension Host log:

[2020-03-31 12:23:48.059] [exthost] [info] ExtensionService#_doActivateExtension pmbenjamin.vscode-snyk {"startup":false,"extensionId":{"value":"pmbenjamin.vscode-snyk","_lower":"pmbenjamin.vscode-snyk"},"activationEvent":"onCommand:extension.snykTest"} [2020-03-31 12:23:48.059] [exthost] [info] ExtensionService#loadCommonJSModule file:///Users/Mikail.Tunc/.vscode/extensions/pmbenjamin.vscode-snyk-0.0.2/extension

Monorepo support

Is it possible to scan monorepos? e.g. scan all package.json in a lerna project

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.