Snyk
Snyk reads a dependency tree as software composition analysis, follows a flaw into indirect packages, and is not tied to one code host.
Why our report names it
Our report names Dependabot and Snyk in the same sentence because they are not one answer given twice. The manifest behind your page is unreadable from outside it, so this question reaches the report through the questionnaire, and Snyk is where the answer points when what you need is the composition of the whole tree rather than an alert feed attached to one hosting provider.
What it doesn't do
- Releases are what it follows, not commits. Snyk's Open Source documentation states that only official releases are identified and that a commit merged to a default branch does not register unless it lands in a release or a tag, so a fix already sitting in main is invisible until somebody publishes it.
- Licence compliance and risk-based prioritisation are both marked absent from the free tier in Snyk's own plans comparison, and they are two of the reasons people move to it in the first place. Those are behind a paid plan.
- The free tier caps how many Projects Snyk will keep monitored, a ceiling that one repository split across a handful of deployable services reaches much sooner than the number suggests.
- It wants a seat inside your development process: a connected repository, or a token on a build machine, or both. That is the opposite of the passive read this site is built around, and it is the reason a dependency question can never be answered by scanning a page.
What it does
- Snyk's documentation frames this as software composition analysis, and the framing earns its keep: most of a modern application is somebody else's code, packages pull in further packages, and the flaw is often sitting in an indirect dependency nobody on your team chose or has heard of.
- Transitive dependency analysis is marked present on every tier of the plans comparison Snyk publishes, its free one included. The question that actually decides whether you have to act, does the vulnerable version really end up in my build, is therefore answerable without buying anything.
- It treats dependencies, your own source, container images and infrastructure definitions as one problem. Snyk marks open source scanning, real-time custom code scanning, infrastructure-as-code scanning and container image scanning as present on its free tier, which is a wider surface than a manifest watcher covers.
More on the problem
Nothing here is gated behind us. Go straight to Snyk and make your own mind up.
Sources
Every claim about Snyk on this page was read on from the pages below. Products change and this page does not change with them, so treat the date as the claim's expiry rather than its publication.
- Snyk's Open Source documentation: that Snyk Open Source is a software composition analysis tool reaching indirect dependencies and licences, and that only official releases are tracked, with commits to a default branch not identified unless released or tagged
- Snyk's plans comparison, read cell by cell from its checkmark markers rather than its labels: transitive dependency analysis, open source, code, infrastructure-as-code and container scanning present on the free tier, licence compliance and risk-based prioritisation absent from it, and a ceiling on the number of monitored Projects
Ready to see where you stand?
Scan your site and get your Engineering Score with a prioritized roadmap in under a minute, no signup required.
EngineeringScore