| Scan type | What it finds | Typical target |
|---|---|---|
| SAST | Vulnerabilities in your own source code | Code written in languages such as Java, JavaScript, etc. |
| SCA | Vulnerabilities in third‑party libraries | Open‑source or proprietary dependencies (e.g., Log4j, Jackson) |
| Container | Misconfigurations and secrets in container images | Docker images or Kubernetes pods |
| IaC | Configuration mistakes in infrastructure code | CloudFormation, Terraform, Azure Resource Manager, etc. |
These scans run automatically in your CI/CD pipeline, giving you early feedback on both code and dependency security.
Objective: Run a Software Composition Analysis scan every time code is pushed.
Edit your pom.xml and add:
<plugin><groupId>io.snyk</groupId><artifactId>snyk-maven-plugin</artifactId><version>2.0.0</version><configuration><orgName>myorg</orgName> *<!-- Your Snyk organization -->*</configuration></plugin>