services / snyk

Snyk IP ranges

Not published. This vendor states that IP allowlisting is not the supported way to secure this integration.

what the vendor says

The Broker Client opens the outbound WebSocket and Snyk rides it back, so in their words 'you do not need to allow a Snyk IP address. Instead, you can allow the Broker Client IP/port.' Requests to Snyk go through a CDN that rotates addresses and whole ranges, and they direct users to allow *.snyk.io.

Source: https://docs.snyk.io/platform-administration/snyk-broker/broker-inbound-and-outbound-connections-and-allowed-requests. That page is where this entry comes from, so you can check it rather than take our word for it.

what to do instead

Pick the control the vendor actually supports, and keep it scoped to the one workload that needs it:

the rest of your stack

One unpinnable dependency does not stop you pinning the others. The catalog covers the vendors that do publish official ranges, and the vendor report scores how well each one publishes.