Snyk plugin

Automatically monitor your projects and deployed code for vulnerabilities and get updates on newly identified vulnerabilities.

Adding a data source

To add a data source click on the + next to Data Sources on the left-hand menu in SquaredUp. Search for the data source and click on it to open the Configure data source page.

Before you start

When configuring the data source, you must enter a Snyk API key to authenticate the connection. For information on generating this API key, see the Snyk authentication for API documentation.

Configuring the data source

  1. Display name:
    Enter a name for your data source. This helps you to identify this data source in the list of your data sources.

  2. API Key:
    Add the Snyk API key you generated. This is used to authenticate the plugin connection.
  3. Index specific organizations:
    Select this check box if you wish to import specific Snyk organizations. The following fields display:
    1. Organization:
      Select this checkbox if you want to import a specific Snyk organization. Then, specify that Organization ID in the field that displays below.
    2. Group:
      Select this checkbox to import organizations and objects that belong to a specific Snyk group. Then, specify that Group ID in the field that displays below.
  4. Restrict access to this data source:
    Optionally, enable this toggle if you only want certain users/groups to have access to the data source, or those with the permission to link it to new workspaces. See data source access control for more information.

  5. Click Test and add to validate the data source configuration. SquaredUp will now attempt to connect to SquaredUp using the provided authentication method.

    • Testing passed – a success message will be displayed and then the configuration will be saved.
    • Testing passed with warnings – warnings will be listed and potential fixes suggested. You can still use the data source with warnings. Select Save with warnings if you believe that you can still use the data source as required with the warnings listed. Alternatively, address the issues listed and then select Rerun tests to validate the data source configuration again. If the validation now passes, click Save.
    • Testing Failed – errors will be listed and potential fixes suggested. You cannot use the data source with errors. You are able to select Save with errors if you believe that a system outside of SquaredUp is causing the error that you need to fix. Alternatively, address the issues listed and then select Rerun tests to validate the data source configuration again. If the validation now passes, click Save.

    You can edit data source configurations at any time from Settings > Data Sources.

Next steps

After configuring the plugin, you can start using its data streams to create dashboards! You can also access the plugin's preconfigured dashboards if you chose to install them.

Preconfigured dashboards

The Key Metrics preconfigured dashboard can be installed with this plugin. This dashboard displays an overview for the Snyk organizations you chose to import and includes visualizations for metrics such as the Total Issues, Time to Resolve Security Issues and a summary of your open security issues.

Data streams

Data streams

You can use these data streams to create new tiles to show data, or if there are preconfigured dashboards installed you can copy or edit those.

Data streams standardize data from all the different shapes and formats your tools use into a straightforward tabular format.

While creating a tile you can tweak data streams by grouping or aggregating specific columns.

Depending on the kind of data, SquaredUp will automatically suggest how to visualize the result, for example as a table or line graph.

Data streams can be either global or scoped:

  • Global data streams are unscoped and return information of a general nature (e.g. "Get the current number of unused hosts").
  • A scoped data stream gets information relevant to the specific set objects supplied in the tile scope (e.g. "Get the current session count for these hosts").

See Data Streams for more information.

The following data streams are installed with this plugin.

Open Security Issues

All issues with open status

Resolved Security Issues

All issues with resolved status

Security Issues

All issues that match the configuration

Parameters
Statistics

Issue counts and related statistics for scoped objects

Was this article helpful?


Have more questions or facing an issue?