Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Snyk Posture Report

Delivers a weekly report on Snyk coverage, what changed, and anything in the account that needs attention, from broken integrations to license limits.

What this agent does

This read-only agent checks the health of a Snyk account every week. It compares the repositories in the source code provider it is connected to with the projects Snyk tests, and it finds repositories that are missing, failing, or no longer tested. It summarizes the issues that appeared, closed, or were ignored since last week. It flags anything that needs an admin, such as a broken integration, an ignore about to expire, or usage close to the plan's limits.

The challenge

Snyk only protects the repositories it tests, and gaps in coverage are easy to miss. New repositories never get imported, an integration token expires, and tests stop running without anyone noticing. Test quotas and developer licenses run out in the middle of a release. Admins find out when something breaks, not before.

The solution

The agent checks coverage, activity, and account limits in one pass each week and compares them with the previous week. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    Compare the organization's repositories with Snyk projects, and find the ones missing, failing to import, or not tested recently.

  2. 02

    Check activity

    Summarize issues that appeared, were fixed, or were ignored since last week, and ignores that expire soon.

  3. 03

    Check the account

    Check integrations, tokens, test usage, and licensed developers against the plan's limits.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Snyk Posture Report

## Measurable outcomes

Every week, the admin knows which repositories Snyk is not covering, what changed in the account, and what needs action before it breaks. Track covered and uncovered repositories and open action items on every run.

## Procedure

Once a week, compare the active repositories in the connected source code provider, such as a GitHub organization, GitLab group, or Bitbucket workspace, with the projects Snyk tests. List the repositories that are not imported, failed to import, or have not been tested in the last week, unless I set another window. Summarize the new Critical and High issues, the issues fixed, and the issues ignored since the last report, with who ignored them and why. List ignores that expire in the next two weeks. Check each source code integration and service token, and flag any that are broken or about to expire. Compare test usage and licensed developers with the plan's limits, and flag anything above 80 percent. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Snyk API access to the organization and read access to the list of repositories in that source code provider, and nothing more. It never changes Snyk settings, projects, or issues.