Cracken + Snyk
Snyk decides a dependency flaw matters by tracing your own code's call graph to it. Cracken attacks the running application. It proves which of those findings an attacker can reach from outside.
Connecting Snyk
- Connect with
A Snyk API token, plus a Snyk base URL if you are not on the default region
- Cadence
Syncs on a schedule — every 6 hours by default
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Snyk
AppSec issues with severity (critical, high, medium, low, info) and state (open, fixed, ignored)
The rule that fired — rule_id — and the file_path it fired on
cve list with cvss_base_score, cvss_vector and cvss_version where Snyk carries them
The affected package — name, version, ecosystem, license — landed as a File node under the Finding when the finding carries one
The repository url the finding came from, landed as a URL node that contains the Finding
first_seen, last_seen, solution and patchable
vendor_id and vendor_severity, Snyk's own labels beside the normalized ones
What Snyk does not do
One read action and nothing else: Cracken lists Snyk findings and never asks Snyk to re-test. There is no write path either — it cannot ignore an issue, open a fix PR or bump a dependency. Self-hosted deployments cannot connect Snyk without the hosted connection service enabled.
How Cracken uses Snyk
- 01
Connect Snyk
- 02
Sync the AppSec findings
- 03
Prove what is reachable at runtime
- 04
Confirm it connected
Frequently asked questions
Does Cracken get access to my source code through Snyk?
No; the Snyk integration lists only findings — severity, state, package, and repository — never your code, which needs a separate integration like GitHub or GitLab.
Does connecting Snyk change my Snyk projects?
No; the integration only lists findings and never opens pull requests, closes issues, changes project settings, or triggers Snyk tests.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations
GitHub Advanced Security
Cracken queries your GitHub repositories and their scanning and Dependabot alerts live.

Aikido
Cracken proves which Aikido issues an attacker can reach from outside.
GitLab
Cracken queries your GitLab projects and vulnerability findings mid-operation.
Attack with real Snyk context.
See how Cracken works what Snyk already knows into attack paths it proves end to end.


