All integrations
Snyk logo
// Data Integration · Application Security

Cracken + Snyk

Snyk decides a dependency flaw matters by tracing your own code's call graph to it. Cracken attacks the running application. It proves which of those findings an attacker can reach from outside.

Get started
// 01

Connecting Snyk

Connect with

A Snyk API token, plus a Snyk base URL if you are not on the default region

Cadence

Syncs on a schedule — every 6 hours by default

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from Snyk

  • AppSec issues with severity (critical, high, medium, low, info) and state (open, fixed, ignored)

  • The rule that fired — rule_id — and the file_path it fired on

  • cve list with cvss_base_score, cvss_vector and cvss_version where Snyk carries them

  • The affected package — name, version, ecosystem, license — landed as a File node under the Finding when the finding carries one

  • The repository url the finding came from, landed as a URL node that contains the Finding

  • first_seen, last_seen, solution and patchable

  • vendor_id and vendor_severity, Snyk's own labels beside the normalized ones

// 03

What Snyk does not do

One read action and nothing else: Cracken lists Snyk findings and never asks Snyk to re-test. There is no write path either — it cannot ignore an issue, open a fix PR or bump a dependency. Self-hosted deployments cannot connect Snyk without the hosted connection service enabled.

// 04

How Cracken uses Snyk

  1. 01

    Connect Snyk

  2. 02

    Sync the AppSec findings

  3. 03

    Prove what is reachable at runtime

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does Cracken get access to my source code through Snyk?

No; the Snyk integration lists only findings — severity, state, package, and repository — never your code, which needs a separate integration like GitHub or GitLab.

Does connecting Snyk change my Snyk projects?

No; the integration only lists findings and never opens pull requests, closes issues, changes project settings, or triggers Snyk tests.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Snyk context.

See how Cracken works what Snyk already knows into attack paths it proves end to end.