Overview
The Snyk integration monitors your application security platform: projects, vulnerabilities, licenses, and dependencies. LowerPlane uses read-only access via an API Token to collect compliance evidence automatically.Prerequisites
How to Get Your Credentials
Log in to Snyk
Log in to your Snyk Dashboard.
Generate an API token
Follow the Snyk documentation to generate your API token. Set the permission to Full Access :: Read.
Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane
- Find Snyk under Security Tools
- Enter your API Token
- Select your Region
- Click Connect
What LowerPlane Monitors
Projects
Monitored projects, scan configurations, and test frequency.
Vulnerabilities
Open vulnerabilities, severity distribution, and fix availability.
Licenses
License compliance across all dependencies.
Dependencies
Dependency trees and outdated package tracking.
Frameworks Supported
| Framework | What It Proves |
|---|---|
| SOC 2 | Vulnerability management and security testing are in place |
| ISO 27001 | Application security and patch management are enforced |
| PCI-DSS | Vulnerability scanning and remediation are maintained |