Skip to content

feat: update agent scan workflow - #7165

Merged
xzhou-snyk merged 1 commit into
mainfrom
feat/ADS-853-use-new-agent-scan-version
Aug 21, 2026
Merged

feat: update agent scan workflow#7165
xzhou-snyk merged 1 commit into
mainfrom
feat/ADS-853-use-new-agent-scan-version

Conversation

@xzhou-snyk

@xzhou-snyk xzhou-snyk commented Aug 21, 2026

Copy link
Copy Markdown
Contributor

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Bumps the version of cli-extension-agent-scan used. This points to v0.6.0 of agent-scan CLI now.

Where should the reviewer start?

Experimental module agent-scan version bump, so no formal communication required.

How should this be manually tested?

/cli/binary-releases/snyk-macos-arm64 agent-scan
--experimental
--show-analysis-results \

What's the product update that needs to be communicated to CLI users?

Output is now changed to risk based instead of issue codes based.

However due to that this is experimental and we don't have any customer usage, (see log) no formal customer communication is needed practically.

It's a breaking change from 0.5.x to 0.6.0 in that the output is now risk based instead of issue codes. So if there were anyone using --json and do some post-processing of the JSON output it would be a breaking change. But we did the analytics lookup already we haven't found any such CI user that processes the JSON output.

In the release notes we could briefly mention the output date from issue codes to risk indicators.

Risk assessment (Low | Medium | High)?

Low

Any background context you want to provide?

snyk/agent-scan#431
snyk/cli-extension-agent-scan#40

What are the relevant tickets?

https://snyksec.atlassian.net/browse/ADS-853

Screenshots (if appropriate)

Screenshot 2026-08-21 at 15 32 19 Screenshot 2026-08-21 at 15 32 32

@xzhou-snyk
xzhou-snyk requested a review from a team as a code owner August 21, 2026 13:33
@snyk-io

snyk-io Bot commented Aug 21, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

This comment has been minimized.

@xzhou-snyk
xzhou-snyk force-pushed the feat/ADS-853-use-new-agent-scan-version branch from 3a30eff to d5451a6 Compare August 21, 2026 13:37
@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 5 relevant code sections from 3 files (average relevance: 0.94)

🤖 Repository instructions applied (from AGENTS.md)

@robertolopezlopez

Copy link
Copy Markdown
Contributor

@xzhou-snyk CI is failing, please ping us again when it will be green to get a new review

@xzhou-snyk
xzhou-snyk merged commit 09c67d4 into main Aug 21, 2026
10 checks passed
@xzhou-snyk
xzhou-snyk deleted the feat/ADS-853-use-new-agent-scan-version branch August 21, 2026 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants