Snyk Security

Compatible with IntelliJ IDEA (Ultimate, Community), Android Studio and 16 more
Screenshot 1
Screenshot 2

JetBrains plugin

Scan early, fix as you develop: elevate your security posture

Integrating security checks early in your development lifecycle helps you pass security reviews seamlessly and avoid expensive fixes down the line.

The Snyk JetBrains plugin allows you to analyze your code, open-source dependencies, Docker images, and Infrastructure as Code (IaC) configurations. With actionable insights directly in your IDE, you can address issues as they arise.

Key features:

  • In-line issue highlighting: Security issues are flagged directly within your code, categorized by type and severity for quick identification and resolution.
  • Comprehensive scanning: The extension scans for a wide range of security issues, including:
  • Broad language and framework support: Snyk Open Source and Snyk Code cover a wide array of package managers, programming languages, and frameworks, with ongoing updates to support the latest technologies. For the most up-to-date information on supported languages, package managers, and frameworks, see the supported language technologies pages.

How to install and set up the extension

The latest Snyk JetBrains plugin is supported by all JetBrains IDEs 2023.3 or newer.

An older plugin version is supported by JetBrains IDEs 2020.3 or newer.

You can use the Snyk JetBrains plugin in the following environments:

  • Linux: 386, AMD64, and ARM64
  • Linux Alpine: 386 and AMD64
  • Windows: 386, AMD64, and ARM64
  • MacOS: AMD64 and ARM64

Install the plugin at any time free of charge from the JetBrains marketplace and use it with any Snyk account, including the Free plan. For more information, see the IDEA plugin installation guide.

When the extension is installed, it automatically downloads the Snyk CLI, which includes the Language Server.

Continue by following the instructions in the other JetBrains plugin docs:

Support

For troubleshooting and known issues, see Troubleshooting for the JetBrains plugin.

If you need help, submit a request to Snyk Support.

What’s New

2.11.0

Changed

  • If $/snyk.hasAuthenticated transmits an API URL, this is saved in the settings.
  • Add "plugin installed" analytics event (sent after authentication)
  • Added a description of custom endpoints to settings dialog.
  • Add option to ignore IaC issues

Fixed

  • only ask to scan folders that are known to language server
  • folder-specific configs are availabe on opening projects, not only on restart of the IDE
  • display open source issues in Rider. Previously, as the project.assets.json is in a derived folder, it was filtered.
  • correctly display and update base branch name for Net New Issues
Jan 09, 2025
Version 2.11.0

Rating & Reviews

2.9
37 Ratings (381,568 Downloads)
5
4
3
2
1

Eric Richards

10.12.2024

I cannot figure out how to make it scan the actual project from the IDE plugin

It it trying to look in this Jetbrains /.run directory that doesn't have anything in it, and I can't figure out what in the hell I need to do to configure it or get the right parameters to it

"error=Could not detect supported target files in F:\Code\MyProject.run. Please see our documentation for supported languages and target files"

The solution file is in F:\Code\MyProject

The CLI tooling is fine, but this just doesn't work and there isn't enough knobs and switches on the plugin to make it work.

I guess I'll see if the Visual Studio plugin is any better.

0

VIRAJ BHOSLE

07.10.2024

Almost never works. one or other error in open source dependency scan.

0

Brian Daley

25.09.2024

I could not find a way to update my negative review I wrote a while back. Everything is working great now.

0

Additional Information

Vendor:
Snyk Ltd(Trader)
Plugin ID:
io.snyk.snyk-intellij-plugin