snyk-ls

command module
v1.1303.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Feb 24, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

README

Snyk Language Server (Snyk-LS)

Build Go binaries Release Go binaries Contributor Covenant

Supported features

The language server follows the Language Server Protocol and integrates with Snyk Open Source, Snyk Infrastructure as Code and Snyk Code. For the former two, it uses the Snyk CLI as a data provider, for the latter it is connecting directly to the Snyk Code API.

Right now the language server supports the following actions:

  • Send diagnostics to client on opening a document if it's part of the current set of folders.
  • Starting a folder scan on startup and sending diagnostics.
  • Starting a workspace scan of all folders on command.
  • Cache diagnostics until saving or triggering a new workspace scan.
  • Invalidate caches on saving a document and retrieve saved document diagnostics anew.
  • Provides range calculation to correctly highlight Snyk Open Source issues in their file.
  • Provides formatted hovers with diagnostic details and follow-up links
  • Progress reporting to the client for background jobs
  • Notifications & Log messages to the client
  • Authentication when needed, using OAuth2 or Token authentication and opening a webpage if necessary
  • Copying the authentication URL to clipboard if there are problems opening a webpage
  • Automatic download of the Snyk CLI if none is found or configured to XDG_DATA_HOME
  • Selective activation of products according to settings transmitted
  • Scanning errors are reported as diagnostics to the Language Server Client
  • Code Lenses to navigate the Snyk Code dataflow from within the editor
  • Code Actions for in-editor commands, like opening a browser, doing a quickfix or opening a Snyk Learn lesson for the found diagnostic
Implemented operations
Language Server Protocol support
Requests
  • initialize
  • exit
  • textDocument/codeAction
  • textDocument/codeLens
  • textDocument/didClose
  • textDocument/didSave
  • textDocument/hover
  • textDocument/inlineValue
  • shutdown
  • workspace/didChangeWorkspaceFolders
  • workspace/didChangeConfiguration
  • workspace/executeCommand
  • window/workDoneProgress/create (from server -> client)
  • window/showMessageRequest
  • window/showDocument
Notifications
  • $/progress

  • $/cancelRequest

  • textDocument/publishDiagnostics

    • params: types.PublishDiagnosticsParams
    • example: Snyk Open Source
    {
      "uri": "file:///path/to/file",
      "diagnostics": [
        {
          "range": {
            "start": { "line": 1, "character": 0 },
            "end": { "line": 2, "character": 0 },
          },
          "severity": 1,
          "code": "S100",
          "source": "Snyk",
          "message": "Message",
          "tags": ["security"],
          "data": {
            "id": "123",
            "issueType": "vulnerability",
            "packageName": "packageName",
            "packageVersion": "packageVersion",
            "issue": "issue",
            "additionalData": {
              "ruleId": "ruleId",
              "identifiers": {
                "cwe": ["cwe"],
                "cve": ["cve"]
              },
              "description": "description",
              "language": "language",
              "packageManager": "packageManager",
              "packageName": "packageName"
            }
          }
        }
      ]
    }
    
    • example: Snyk Code
    {
      "uri": "file:///path/to/file",
      "diagnostics": [
        {
          "range": {
            "start": { "line": 1, "character": 0 },
            "end": { "line": 2, "character": 0 },
          },
          "severity": 1,
          "code": "S100",
          "source": "Snyk",
          "message": "Message",
          "tags": ["security"],
          "data": {
            "id": "123",
            "filePath": "filePath",
            "range": {
              "start": { "line": 1, "character": 0 },
              "end": { "line": 2, "character": 0 },
            },
            "additionalData": {
              "message": "message",
              "rule": "rule",
              "ruleId": "ruleId",
              "dataFlow": [
                {
                  "filePath": "filePath",
                  "range": {
                    "start": { "line": 1, "character": 0 },
                    "end": { "line": 2, "character": 0 },
                  },
                }
              ],
              "cwe": "cwe",
              "isSecurityType": true
            }
          }
        }
      ]
    }
    
  • window/logMessage

  • window/showMessage

Custom additions to Language Server Protocol (server -> client)
  • SDKs callback to retrieve configured SDKs from the client

    • method: workspace/snyk.sdks
    • params: types.WorkspaceFolder
    • example:
    [{
      "type": "java", // or python or go
      "path": "/path/to/sdk" // JAVA_HOME for java, GOROOT for Go, Python executable for Python
    }]
    
  • Folder Config Notification

    • method: $/snyk.folderConfigs
    • params: types.FolderConfigsParam
    • example:
    {
        "folderConfigs":
        [
          {
            "folderPath": "the/folder/path",
            "baseBranch": "the-base-branch", // e.g. main
            "localBranches": [ "branch1", "branch2" ],
            "preferredOrg": "org-id", // Organization to use when operating on this folder.
            "orgMigratedFromGlobalConfig": true, // Set by language server to track migrations over upgrade.
            "orgSetByUser": true // If false, Language Server determines the organization automatically.
          }
        ]
    }
    
  • Custom Publish Diagnostics Notification

    • method: $/snyk.publishDiagnostics316
    • params: types.PublishDiagnosticsParams
    • note: alias for textDocument/publishDiagnostics
  • Authentication Notification

    • method: $/snyk.hasAuthenticated
    • params: types.AuthenticationParams
    • example:
    {
      "token": "the snyk token", // this can be an oauth2.Token string or a legacy token
      "apiUrl": "https://api.snyk.io"
    }
    
  • CLI Path Notification

    • method: $/snyk.isAvailableCli
    • params: types.SnykIsAvailableCli
    • example:
    {
      "cliPath": "/a/path/to/cli-executable"
    }
    
  • Trusted Folder Notification

    • method: $/snyk.addTrustedFolders
    • params: types.SnykTrustedFoldersParams
    • example:
    {
      "trustedFolders": ["/a/path/to/trust"]
    }
    
  • Scan Notification

    • method: $/snyk.scan
    • params: types.ScanParams
    • example: Successful scan
    {
      "status": "success", // possible values: "error", "inProgress", "success"
      "product": "code", // possible values: "code", "oss", "iac"
      "folderPath": "/a/path/to/folder",
    }
    
    • example: Failed scan with errors
    {
      "status": "error",
      "product": "code",
      "folderPath": "/a/path/to/folder",
      "presentableError": {
        "cliError": {
          "code": "CLI_ERROR_CODE",
          "error": "An error occurred"
        },
        "showNotification": true,
        "treeNodeSuffixError": "(failed)"
      }
    }
    
  • Summary Panel Status Notification

    • method: $/snyk.scanSummary
    • params: types.ScanSummary
    • example:
    {
      "scanSummary": "<html><body<p> Summary </p></body></html>"
    }
    
  • Register MCP Notification

    • method: $/snyk.registerMcp
    • params: types.SnykRegisterMcpParams
    • example:
      {
        "command": "/path/to/cli",
        "args": [ "mcp", "-t", "stdio" ],
        "env": {
          "ENV1": "value1",
          "ENV2": "value2"
        }
      }
    
Commands
  • NavigateToRangeCommand navigates the client to the given range

    • command: snyk.navigateToRange
    • args: path, Range
  • WorkspaceScanCommand triggers a scan of all workspace folders

    • command: snyk.workspace.scan
    • args: empty
  • WorkspaceFolderScanCommand triggers a scan of the given workspace folder

    • command: snyk.workspaceFolder.scan
    • args: path
  • OpenBrowserCommand opens the given URL in the default browser

    • command: snyk.openBrowser
    • args: URL
  • LoginCommand triggers the login process

    • command: snyk.login
    • args: empty
  • CopyAuthLinkCommand copies the authentication URL to the clipboard

    • command: snyk.copyAuthLink
    • args: empty
  • LogoutCommand triggers the logout process

    • command: snyk.logout
    • args: empty
  • TrustWorkspaceFoldersCommand checks for trusted workspace folders and asks for trust if necessary

    • command: snyk.trustWorkspaceFolders
    • args: empty
  • OpenLearnLesson opens the given lesson on the Snyk Learn website

    • command: snyk.openLearnLesson
    • args:
      • rule string
      • ecosystem string
      • cwes string (comma separated), e.g. CWE-79,CWE-89
      • cves string (comma separated), e.g. CVE-2018-11776,CVE-2018-11784
      • issueType int
      PackageHealth Type = 0
      CodeSecurityVulnerability = 1
      LicenceIssue = 2
      DependencyVulnerability = 3
      InfrastructureIssue = 4
      
  • GetLearnSession returns the given lesson on the Snyk Learn website

    • command: snyk.getLearnLesson
    • args:
      • rule string
      • ecosystem string
      • cwes string (comma separated), e.g. CWE-79,CWE-89
      • cves string (comma separated), e.g. CVE-2018-11776,CVE-2018-11784
      • issueType int
      PackageHealth Type = 0
      CodeSecurityVulnerability = 1
      LicenceIssue = 2
      DependencyVulnerability = 3
      InfrastructureIssue = 4
      
    • result: lesson json
    {
    "lessonId": "123",
    "datePublished": "2022-01-01",
    "author": "John Doe",
    "title": "Introduction to Golang",
    "subtitle": "A beginner's guide to Golang",
    "seoKeywords": ["Golang", "Programming", "Beginner"],
    "seoTitle": "Learn Golang",
    "cves": ["CVE-2022-1234", "CVE-2022-5678"],
    "cwes": ["CWE-123", "CWE-456"],
    "description": "This lesson provides an introduction to Golang for beginners",
    "ecosystem": "Programming",
    "rules": ["Rule 1", "Rule 2", "Rule 3"],
    "slug": "golang-intro",
    "published": true,
    "url": "https://example.com/golang-intro",
    "source": "Example.com",
    "img": "https://example.com/images/golang-intro.png"
    }
    
  • SettingsSastEnabled triggers the api call to check if Snyk Code is enabled

    • command: snyk.getSettingsSastEnabled
    • args: empty
    • returns a *sast_contract.SastResponse or, or an error and false if an error occurred
  • GetActiveUser triggers the api call to get the active logged in user or an error if not logged in

    • command: snyk.getActiveUser
    • args: empty
    • returns the active user and its orgs and groups or an error if not logged in.
    {
      "id": "123",
      "username": "johndoe",
      "orgs": [
       {
         "name": "org1",
         "id": "org1_id",
         "group": {
            "name": "group1",
            "id": "group1_id"
         }
       }
      ],
    }
    
  • Code Fix Command triggers an autofix and applies the changes of the first suggestion

    • command: snyk.code.fix
    • args:
      • codeActionId string
      • AffectedFilePath string
      • range Range
    • returns an error if not successful
  • Code Fix Diffs allows to retrieve the diffs for autofix suggestions

    • command: snyk.code.fixDiffs
    • args:
      • issueID string (UUID)
    • returns an array of suggestions:
    [{
      "fixId": "123",
      "unifiedDiffsPerFile": {
        "path/to/file": "diff"
      }
    }]
    
    • Diff Example:
    
    --- /var/folders/vn/77lwfy3974g7vykcm5lr6mkh0000gn/T/Test_SmokeWorkspaceScanOssAndCode952013010/001/1
    +++ /var/folders/vn/77lwfy3974g7vykcm5lr6mkh0000gn/T/Test_SmokeWorkspaceScanOssAndCode952013010/001/1-fixed
    @@ -32,7 +32,8 @@
    
         test('should set success to OK upon success', function() {
           // GIVEN
    
    -      comp.password = comp.confirmPassword = 'myPassword';
    
    +      comp.password = process.env.TEST_PASSWORD;
    +      comp.confirmPassword = process.env.TEST_PASSWORD;
    
           // WHEN
           comp.changePassword();
    
  • Code Fix Apply Edit Command triggers an autofix and applies the changes of the first suggestion

  • Feature Flag Status Command triggers the api call to check if a feature flag is enabled

    • command: snyk.getFeatureFlagStatus
    • args:
      • featureFlagType string
    • returns an object with the status of the feature flag and an optional user message
      {
        "ok": true, // boolean indicating if the feature is enabled (true or false)
        "userMessage": "Optional message to the user" // present if 'ok' is false
      }
    
  • Clear Cache Clears either persisted or inMemory Cache or both.

    • command: snyk.clearCache
    • args:
      • folderUri string,
      • cacheType persisted or inMemory
  • Generate Issue Description Generates issue description in HTML.

    • command: snyk.generateIssueDescription
    • args:
      • issueId string
  • Configuration Dialog Opens the configuration dialog with all Snyk settings.

    • command: snyk.workspace.configuration
    • args: empty
    • returns: HTML string containing the configuration dialog
    • example:
    <html>
      <head>
        <title>Snyk Configuration</title>
        ...
      </head>
      <body>
        <!-- Configuration form with all settings -->
      </body>
    </html>
    

Installation

Download

The release workflow stores the generated executables, so that they can be downloaded here. Just select the release you want the build artefacts from and download the zip file attached to it. Currently, executables for Windows, macOS and Linux are generated.

The currently published binary can be retrieved with this bash script, please keep in mind that the protocol version is part of the download link and can change to force plugin / language server synchronization. For further information please see CONTRIBUTING.md.

From Source
  • Install go 1.20 or higher, set the GOPATH and GOROOT
  • Enter the root directory of this repository
  • Execute go get ./... to download all dependencies
  • Execute make build && make install to produce a snyk-ls binary

Configuration

Snyk LSP Command Line Flags

-c <FILE> allows to specify a config file to load before all others

-f <FILE> allows you to specify a log file instead of logging to the console

-l <LOGLEVEL> <allows to specify the log level (trace, debug, info, warn, error, fatal). The default log level is info. This can be overruled by setting the env variable SNYK_DEBUG_LEVEL, e.g. export SNYK_DEBUG_LEVEL=debug

-licenses (running standalone) displays the licenses used by Language Server
--licenses (running within Snyk CLI)

-o <FORMAT> allows to specify the output format (md or html) for issues

-v prints the version of the Language Server

Configuration
LSP Initialization Options

As part of the Initialize message within initializationOptions?: LSPAny; we support the following settings:

{
  "activateSnykOpenSource": "true", // Enables Snyk Open Source - defaults to true
  "activateSnykCode": "false", // Enables Snyk Code, if enabled for your organization - defaults to false, deprecated in favor of specific Snyk Code analysis types
  "activateSnykIac": "true", // Enables Infrastructure as Code - defaults to true
  "insecure": "false", // Allows custom CAs (Certification Authorities)
  "endpoint": "https://api.eu.snyk.io", // Snyk API Endpoint required for non-default multi-tenant and single-tenant setups
  "organization": "a string", // The name of your organization, e.g. the output of: curl -H "Authorization: token $(snyk config get api)"  https://api.snyk.io/v1/cli-config/settings/sast | jq .org
  "path": "/usr/local/bin", // Adds to the system path used by the CLI
  "cliPath": "/a/patch/snyk-cli", // The path where the CLI can be found, or where it should be downloaded to
  "token": "secret-token", // The Snyk token, e.g.: snyk config get api or a token from authentication flow
  "integrationName": "ECLIPSE", // The name of the IDE or editor the LS is running in
  "integrationVersion": "1.0.0", // The version of the IDE or editor the LS is running in
  "automaticAuthentication": "true", // Whether LS will automatically authenticate on scan start (default: true)
  "deviceId": "a UUID", // A unique ID from the running the LS, used for telemetry
  "filterSeverity": { // Optional filter to be applied for the determined issues (if omitted: no filtering)
    "critical": true,
    "high": true,
    "medium": true,
    "low": true,
  },
  "riskScoreThreshold": 400, // Optional filter to be applied for the determined issues (if omitted: no filtering) (valid range: 0-1000)
  "issueViewOptions": { // Optional filter to be applied for the determined issues (if omitted: no filtering)
    "openIssues": true,
    "ignoredIssues": false,
  },
  "sendErrorReports": "true", // Whether to report errors to Snyk - defaults to true
  "manageBinariesAutomatically": "true", // Whether CLI/LS binaries will be downloaded & updated automatically
  "enableTrustedFoldersFeature": "true", // Whether LS will prompt to trust a folder (default: true)
  "activateSnykCodeSecurity": "false", // Enables Snyk Code Security reporting
  "activateSnykCodeQuality": "false", // Enable Snyk Code Quality issue reporting (Beta, only in IDEs and LS)
  "scanningMode": "auto", // Specifies the mode for scans: "auto" for background scans or "manual" for scans on command
  "authenticationMethod": "oauth", // Specifies the authentication method to use: "token" for Snyk API token or "oauth" for Snyk OAuth flow. Default is token.
  "snykCodeApi": "https://deeproxy.snyk.io", // Specifies the Snyk Code API endpoint to use. Default is https://deeproxy.snyk.io
  "enableSnykLearnCodeActions": "true", // show snyk learns code actions
  "enableSnykOSSQuickFixCodeActions": "true", // show quickfixes for supported OSS package manager issues
  "enableSnykOpenBrowserActions": "false", // show code actions to open issue descriptions
  "enableDeltaFindings": "false", // only display issues that are not new and thus not on the base branch
  "requiredProtocolVersion": "14", // the protocol version a client needs
  "hoverVerbosity": "1", // 0-3 with 0 the lowest verbosity. 0: off, 1: only description, 2: description & details 3: complete (default)
  "outputFormat": "md", // plain = plain, markdown = md (default) or html = HTML
  "additionalParams": "--all-projects", // Any extra params for Open Source scans using the Snyk CLI, separated by spaces
  "additionalEnv": "MAVEN_OPTS=-Djava.awt.headless=true;FOO=BAR", // Additional environment variables, separated by semicolons
  "trustedFolders": [
    "/a/trusted/path",
    "/another/trusted/path"
  ], // An array of folder that should be trusted
  "folderConfigs": [{
    "folderPath": "a/b/c", // the workspace folder path
    "baseBranch": "main", // the base branch for delta scanning
    "localBranches": [ "feature-branch" ], // local branches for scanning
    "additionalParameters": [ "--file=pom.xml" ], // additional parameters for CLI scans
    "referenceFolderPath": "reference/path", // optional reference folder for post-scan comparison
    "scanCommandConfig": {}, // scan command configuration per product
    "preferredOrg": "org-id", // preferred organization ID for this folder
    "orgMigratedFromGlobalConfig": false, // internal flag for org migration tracking
    "orgSetByUser": true // whether the org was explicitly set by the user
  }], // an array of folder configurations, defining settings per workspace folder
}

activateSnykCode automatically toggles the value of activateSnykCodeSecurity and activateSnykCodeQuality. Therefore, to enable only one of the two analysis types, activateSnykCode must be removed from Initialization Options for the specific analysis type option to have an effect.

Workspace Trust

As part of examining the codebase for vulnerabilities, Snyk may automatically execute code on your computer to obtain additional data for analysis. For example, this includes invoking the package manager (e.g., pip, gradle, maven, yarn, npm, etc.) to get dependency information for Snyk Open Source. Invoking these programs on untrusted code that has malicious configurations may expose your system to malicious code execution and exploits.

To safeguard from using the language server on untrusted folders, our language server will ask for folder trust before running scans against these folders. When in doubt, do not grant trust.

The trust feature is enabled by default. When a folder is trusted, all sub-folders are also trusted. After a folder is trusted, Snyk Language Server notifies the Language Server Client with the custom $/snyk.addTrustedFolders notification, which contains a list of currently trusted folder paths. Based on this, a client can then implement logic to intercept this notification and persist the decision and trust in the IDE or Editor storage mechanism.

Trust dialogs can be disabled by setting enableTrustedFoldersFeature to false in the initialization options. This will disable all trust prompts and checks.

An initial set of trusted folders can be provided by setting trustedFolders to an array of paths in the initializationOptions. These folders will be trusted on startup and will not prompt the user to trust them.

Environment variables

Snyk LS and Snyk CLI support and need certain environment variables to function:

  1. HTTP_PROXY, HTTPS_PROXY and NO_PROXY to define the http proxy to be used
  2. JAVA_HOME to analyse Java JVM-based projects via Snyk CLI
  3. PATH to find maven when analysing Maven projects, to find python, etc
Auto-Configuration

To automatically add these variables to the environment, Snyk LS searches for the following files, with the order determining precedence. If the executable is not called from an already configured environment (e.g. via zsh -i -c 'snyk-ls'), you can also specify config file with the -c command line flag for setting the above mentioned variables. Snyk LS reads the following files in the given precedence and order, not overwriting the already loaded variables.

given config file via -c flag
<working-dir>/.snyk.env
$HOME/.snyk.env

Any lines that contain an environment variable in the format VARIABLENAME=VARIABLEVALUE are added automatically to the environment if not already existent. This adheres to the dotenv format. In case of .profile, .zshrc, etc., if a variable is directly exported e.g. via export VARIABLENAME=VARIABLEVALUE, it is not loaded. The export would need to be split of and be in its own line, e.g

VARIABLENAME=VARIABLEVALUE
export VARIABLENAME

The PATH variable is treated differently than all other variables, as it is an aggregate of all PATH variables found in the files and in the environment. Also, the current working directory . is automatically added to the path, so a download of the Snyk CLI into the current working directory by an LSP client would yield a found Snyk CLI for the Language Server.

In addition to configuring variables via config files, Snyk LS adds the following directories to the path on linux and macOS:

  • /bin
  • $HOME/bin
  • /usr/local/bin
  • $JAVA_HOME/bin

If no JAVA_HOME is set, it automatically searches for a java executable first in path, then in the following directories and adds the parent directory of its parent as JAVA_HOME. The following directories are recursively searched:

  • /usr/lib
  • /usr/java
  • /opt
  • /Library
  • $HOME/.sdkman
  • C:\Program Files
  • C:\Program Files (x86)

The same directories are searched for a maven executable and the parent directory is added to the path.

Snyk CLI

To find the automatically managed Snyk CLI, the XDG Data Home and PATH path are automatically scanned for the OS-dependent file, e.g. snyk-macos on macOS, snyk-linux on Linux and snyk-win.exe on Windows, and the first path where it is found is added to the environment. It is later used for all functionality that depends on the CLI.

Setting environment variables globally

If you want to have the environment variables available system-wide, you would need to add the variables to /etc/environment or on macOS to /etc/launchd.conf or set them via launchctl in a shell script. The former two locations are automatically read by snyk lsp. On Windows, a user variable can be defined via the UI for the user or system-wide. In a file like ~/.profile it would like this:

SNYK_TOKEN=<your-token-from-app.snyk.io>
DEEPROXY_API_URL=https://deeproxy.snyk.io/

# export variables, but make sure the export is not on the same line as the variable definition
export SNYK_TOKEN
export DEEPROXY_API_URL
Authentication to Snyk

The Snyk LS authentication flow happens automatically, unless disabled in configuration, and is as follows. When Snyk Language Server starts, it:

  • If the endpoint is a snykgov.io endpoint, or the authenticationMethod is set to oauth, it authenticates via OAuth2. This opens a browser window.
  • If the authentication method is not oauth, it tries to retrieve a token using the Snyk CLI token authentication.
  • If the CLI is not authenticated either, it opens a browser window to authenticate
  • If there are problems opening the browser window, the auth URL can be copied to the clipboard (via implementation of snyk.copyAuthLink). Note that there is a requirement to have xsel or xclip installed for Linux/Unix users for this feature.

After successfull authentication in the web browser, the Snyk Language Server automatically retrieves the Snyk authentication credentials and uses them for further requests.

Run Tests

go test ./...

If you have any issues with running pact, please extend your PATH env. For example:

PATH=$PATH:$PWD/.bin/pact/bin make test

The output should look like this (it is running against the Snyk Code API and using the real CLI):

?       github.com/snyk/snyk-ls        [no test files]
ok      github.com/snyk/snyk-ls/code   24.201s
ok      github.com/snyk/snyk-ls/diagnostics    26.590s
ok      github.com/snyk/snyk-ls/iac    25.780s
?       github.com/snyk/snyk-ls/lsp    [no test files]
ok      github.com/snyk/snyk-ls/oss    22.427s
ok      github.com/snyk/snyk-ls/server 48.558s
ok      github.com/snyk/snyk-ls/util   9.562s

Test Github Action locally

You can test github actions locally using act.

Install act & prerequisites
brew install act

# if you don't have docker desktop you can use minikube (a one-node kubernetes distribution)
brew install --cask virtualbox # you need to enable the virtualbox extension in macOS settings
brew install minikube
minikube start
eval $(minikube docker-env) # gives you a fully functional docker environment
Run act
act --secret SNYK_TOKEN=$SNYK_TOKEN --secret DEEPROXY_API_URL=$DEEPROXY_API_URL

Documentation

The Go Gopher

There is no documentation for this package.

Directories

Path Synopsis
application
codeaction
Package codeaction implements the code action functionality
Package codeaction implements the code action functionality
config
Package config implements the configuration functionality
Package config implements the configuration functionality
di
Package di implements the dependency injection functionality
Package di implements the dependency injection functionality
entrypoint
Package entrypoint implements the entrypoint functionality
Package entrypoint implements the entrypoint functionality
server
Package server implements the server functionality
Package server implements the server functionality
server/notification
Package notification implements the scan notifications
Package notification implements the scan notifications
watcher
Package watcher implements file watcher functionality
Package watcher implements file watcher functionality
ast
Package ast implements abstract syntax tree functionality
Package ast implements abstract syntax tree functionality
maven
Package maven implements the Maven parser
Package maven implements the Maven parser
domain
ide/codelens
Package codelens implements the codelens functionality
Package codelens implements the codelens functionality
ide/command
Package command implements the commands available for IDEs
Package command implements the commands available for IDEs
ide/command/mock
Package mock_command is a generated GoMock package.
Package mock_command is a generated GoMock package.
ide/converter
Package converter implements conversions between Snyk and LSP types
Package converter implements conversions between Snyk and LSP types
ide/hover
Package hover implements the hover functionality
Package hover implements the hover functionality
ide/initialize
Package initialize implements initialization functionality
Package initialize implements initialization functionality
ide/workspace
Package workspace implements an LSP workspace
Package workspace implements an LSP workspace
scanstates
Package scanstates implements scan state management
Package scanstates implements scan state management
snyk
Package snyk implements the Snyk Domain types & functionality
Package snyk implements the Snyk Domain types & functionality
snyk/delta
Package delta implements delta scanning
Package delta implements delta scanning
snyk/mock_snyk
Package mock_snyk is a generated GoMock package.
Package mock_snyk is a generated GoMock package.
snyk/persistence
Package persistence implements persistence functionality
Package persistence implements persistence functionality
snyk/persistence/mock_persistence
Package mock_persistence is a generated GoMock package.
Package mock_persistence is a generated GoMock package.
snyk/scanner
Package scanner defines the scanner interface and common functionality used in all scanners
Package scanner defines the scanner interface and common functionality used in all scanners
infrastructure
analytics
Package analytics implements analytics functionality
Package analytics implements analytics functionality
authentication
Package authentication implements authentication functionality
Package authentication implements authentication functionality
cli
Package cli provides implementations for handling the Snyk CLI There is OS-specific code, see https://www.digitalocean.com/community/tutorials/building-go-applications-for-different-operating-systems-and-architectures for more information on how that works
Package cli provides implementations for handling the Snyk CLI There is OS-specific code, see https://www.digitalocean.com/community/tutorials/building-go-applications-for-different-operating-systems-and-architectures for more information on how that works
cli/cli_constants
Package cli_constants provides constants for the CLI
Package cli_constants provides constants for the CLI
cli/filename
Package filename implements os specific filename functionality
Package filename implements os specific filename functionality
cli/install
Package install implements the Snyk CLI installation functionality
Package install implements the Snyk CLI installation functionality
code
Package code provides Snyk Code (SAST) scanning functionality.
Package code provides Snyk Code (SAST) scanning functionality.
code/encoding
Package encoding implements encoding functionality
Package encoding implements encoding functionality
configuration
Package configuration provides HTML rendering for the configuration dialog.
Package configuration provides HTML rendering for the configuration dialog.
featureflag
Package featureflag implements remote feature flag support
Package featureflag implements remote feature flag support
filesystem
Package filesystem defines basic interfaces to a file system.
Package filesystem defines basic interfaces to a file system.
iac
Package iac implements the IAC scanner
Package iac implements the IAC scanner
learn
Package learn implements the Snyk Learn API Integration
Package learn implements the Snyk Learn API Integration
learn/mock_learn
Package mock_learn is a generated GoMock package.
Package mock_learn is a generated GoMock package.
oss
Package oss implements the OSS scanner
Package oss implements the OSS scanner
sentry
Package sentry implements the Sentry error reporting functionality
Package sentry implements the Sentry error reporting functionality
snyk_api
Package snyk_api implements the Snyk API client
Package snyk_api implements the Snyk API client
utils
Package utils provides utilities and is mainly used for delta scanning
Package utils provides utilities and is mainly used for delta scanning
Package env provides utilities for environment variables.
Package env provides utilities for environment variables.
concurrency
Package concurrency implements concurrency utilities
Package concurrency implements concurrency utilities
constants
Package constants provides constants
Package constants provides constants
context
Package context implements context management for Snyk
Package context implements context management for Snyk
data_structure
Package data_structure implements data structure functionality
Package data_structure implements data structure functionality
debounce
Package debounce implements debouncer functionality
Package debounce implements debouncer functionality
delta
Package delta implements delta scanning
Package delta implements delta scanning
fflags
Package fflags implements the feature flag functionality
Package fflags implements the feature flag functionality
float
Package float implements float functionality
Package float implements float functionality
html
Package html implements HTML functionality for the IDE clients
Package html implements HTML functionality for the IDE clients
logging
Package logging implements a zerolog writer that sends log messages to the LSP server
Package logging implements a zerolog writer that sends log messages to the LSP server
mcp
Package mcp implements MCP configure workflow call
Package mcp implements MCP configure workflow call
notification
Package notification implements notification functionality for Snyk
Package notification implements notification functionality for Snyk
observability/error_reporting
Package error_reporting implements error reporting functionality
Package error_reporting implements error reporting functionality
observability/performance
Package performance implements performance instrumentation and tracing
Package performance implements performance instrumentation and tracing
product
Package product contains general product names and information for Snyk product lines
Package product contains general product names and information for Snyk product lines
progress
Package progress implements the progress functionality
Package progress implements the progress functionality
scans
Package scans contains functionality related to Snyk scans
Package scans contains functionality related to Snyk scans
sdk
Package sdk implements SDK environment handling
Package sdk implements SDK environment handling
storage
Package storage implements the GAF storage interface for configuration
Package storage implements the GAF storage interface for configuration
storedconfig
Package storedconfig implements stored configuration functionality
Package storedconfig implements stored configuration functionality
testsupport
Package testsupport contains test helpers for Snyk
Package testsupport contains test helpers for Snyk
testutil
Package testutil implements test setup functionality
Package testutil implements test setup functionality
testutil/workspaceutil
Package workspaceutil provides workspace setup utilities for tests.
Package workspaceutil provides workspace setup utilities for tests.
types
Package types provides commonly used types
Package types provides commonly used types
types/mock_types
Package mock_types is a generated GoMock package.
Package mock_types is a generated GoMock package.
uri
Package uri implements URI handling for Snyk
Package uri implements URI handling for Snyk
user_interface
Package user_interface implements the user interface functionality
Package user_interface implements the user interface functionality
util
Package util implements utility functions
Package util implements utility functions
vcs
Package vcs implements VCS integration
Package vcs implements VCS integration
Package ls_extension implements the language server extension for integration with GAF
Package ls_extension implements the language server extension for integration with GAF
scripts
config-dialog command
ABOUTME: Manual test script to generate configuration dialog HTML for visual inspection ABOUTME: Run with: go run scripts/config-dialog/main.go > config_output.html
ABOUTME: Manual test script to generate configuration dialog HTML for visual inspection ABOUTME: Run with: go run scripts/config-dialog/main.go > config_output.html

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL