Container: Go standard library vulnerability reporting
Snyk Container will automatically report vulnerabilities found in the Go standard library for all container images built from Go binaries. The stdlib dependency is now included in the dependency graph versioned to the Go release used for the build, with automatic detection enabled for all organizations starting October 7, 2026.
Snyk Container will begin reporting vulnerabilities from the Go standard library for all customers. Scans of container images built from Go binaries identify the standard library version the binary was compiled with and report known vulnerabilities against it.
Affected images gain a new stdlib dependency in the dependency graph, versioned to the Go release used for the build, for example stdlib@1.25.10. Detection works for standard, stripped, and CGo builds.
No configuration is required, and reporting is enabled automatically for all organizations. Standard library reporting in the Snyk CLI requires v1.1303.2 or later.
This change is scheduled to take effect on October 7, 2026.
Source: original entry ↗
More from Snyk
Follow Snyk to get its new changes in your feed and email digest.
ADS installer now available as packaged binary
The Agent Supply Chain Security installer now ships as signed macOS .pkg and Windows .msi packages, eliminating the need for custom scripts and MDM integration. The installer registers scheduled jobs automatically for independent scan execution.
Snyk CLI v1.1307.4 — Studio integration and snyk fix improvements
Snyk CLI v1.1307.4 adds experimental studio command for AI coding tool integration, new filtering flags for snyk fix --agentic mode, improved fix change handling, and fixes an issue where scan type flags could be silently dropped on unified test API.
Snyk Code Priority Score Updated: Fix Example Factor Removed
Fix example scoring factor was removed from Snyk Code priority scores on August 17, 2026, causing scores to drop by up to 200 points for affected findings. This change aligns priority scoring more closely with actual code risk rather than content availability.