Snyk Projects now stay in sync with repository content
Snyk now automatically keeps your Projects synchronized with repository changes. When files are added, moved, or deleted in monitored branches, Snyk automatically creates or deactivates corresponding Projects, eliminating the need for manual re-imports.
The "What"
Repo Content Sync keeps your Snyk Projects aligned with what your repositories actually contain. When a change is merged to a branch Snyk monitors, Snyk creates and begins monitoring Projects for newly added manifest, Dockerfile, and configuration files, and deactivates the Projects whose files were removed. A file that is moved or renamed is picked up at its new path, and the Project at the old path is deactivated. Until now, keeping Snyk in step with a repository was a manual step: someone re-imported the repository, or a newly added dependency file simply went unscanned. Repo Content Sync makes repository content itself the trigger, so your Project list reflects the code as it is today rather than as it was at import. Sync covers Code, open source, secrets, infrastructure as code, and container (Dockerfile) Projects, and it works on custom branches as well as default branches.
Repo Content Sync will be rolled out gradually over the next several weeks.
Source: original entry ↗