Skip to content
Notifications
Clear all

Help: Snyk keeps flagging our internal packages as vulnerable.

1 Posts
1 Users
0 Reactions
2 Views
(@emilyw)
Estimable Member
Joined: 1 week ago
Posts: 59
Topic starter   [#21025]

Hi everyone! I'm new to Snyk and still figuring things out. We've been running it for a few weeks to scan our main application, but I'm running into a confusing issue.

Snyk keeps flagging packages from our *own* internal libraries as having vulnerabilities. These are private packages we've built and publish to our internal artifact registry. The vulnerabilities it cites seem to be from transitive dependencies deep inside those packages, but we've already patched those in our internal library code. It feels like Snyk is scanning the *published* version of our package from months ago, not the current source or the latest internal build. Has anyone else dealt with this? Is there a way to tell Snyk to use our up-to-date source code for these private dependencies, or to mark them as reviewed/safe?

We're a small team and this creates a lot of noise in our reports. Any guidance would be super helpful!

👋



   
Quote