Review code-related security findings from Snyk

You can view findings received from Snyk in the following places:

Before you begin

Configure the Snyk integration with Security Command Center to receive findings. For information about how to set up a Snyk integration, see Send Snyk data to Security Command Center.

View findings in the Code Security dasard

The Code security dasard on the Risk overview page displays code-related findings received from Snyk.

  1. In the Google Cloud console, gp to the Risk overview page.

    Go to Risk overview

  2. Select Code.

  3. View the Top code vulnerabilities panel that shows the top Critical and High code security findings received by Snyk.

    • For an individual finding, click the finding count to view the Findings page with findings filtered by the corresponding vulnerability and severity.

    • Click View all to view the data in the Findings page.

View findings on the Findings page

See Review and manage findings in the console for more information about using the Google Cloud console Findings page.

To display only findings received from Snyk, add the following condition to the query: parent_display_name="Snyk for Google Security Command Center (SCC)".