Snyk CS Integration

Prerequisites

To ensure uninterrupted access to all required data, the selected user must be assigned the Org Admin role.

Integration Setup

To integrate Snyk with Invicti ASPM:

  1. Navigate to the Account Settings section in Snyk to obtain the user API key
  2. Use this API key to complete the integration within Invicti ASPM
❗️

Organization-level API keys are not supported for this integration. In order for scans to run successfully, a user-level API key must be provided.

When integrating with Invicti ASPM, a Region must be selected along with the Access Token. The Region can be identified based on the URL used when the token was created. The URLs corresponding to each Region are listed below.

The Target Mode option is selected based on the structure of container scans within the organization. If a project contains multiple images in projects this option needs to be enabled.

Scan Configuration

After completing the integration, Scan Parameters can be added at the project level. During scan configuration, selecting the Organization and Project is sufficient to proceed with the setup.