project_snapshot/v0 event every time it retests a project: each issue in newIssues opens a Flashduty alert, and each issue in removedIssues recovers its alert.
Snyk webhooks currently cover Open Source and Container scans. The Webhooks API is in beta and is available only in the Snyk US-01, US-02, EU-01, and AU-01 regions.
In Flashduty On-call
You can get the integration push URL in either of the following ways.
Use a dedicated integration
- Open the Flashduty console, choose Channels, and open a channel
- Choose Settings → Integrations → Dedicated integrations, then click Add an integration
- Choose Snyk and click Save
- Open the generated integration card and copy the push URL
Use a shared integration
- Open the Flashduty console and choose Integration Center → Alert events
- Choose Snyk and enter an integration name
- Configure the default route and pick a channel; you can add more rules under Routes after creation
- Click Save and copy the generated push URL
In Snyk
Snyk webhooks can only be created through the API; the Snyk web console has no entry for them.
1
Prepare Snyk credentials
You need your Snyk organization ID and an API token. A webhook belongs to an organization, so the token must have access to that organization.The organization’s plan must include API access. On the Free plan the Webhooks API fails with
The org <name> (<id>) is not entitled for api access. Please upgrade your plan. Start the free 14-day trial under Settings → Billing → Available plans, or upgrade the plan, and then create the webhook.2
Create the webhook
Call the Create a webhook API. Set The response
url to the full Flashduty push URL (Snyk accepts HTTPS URLs only) and secret to a random string only you know:id is the webhook ID, which you need for testing and deleting the webhook.3
Send a test
Snyk sends a The test event opens a separate Info alert in Flashduty titled
ping/v0 event right after the webhook is created. You can send it again with the ping API:Snyk test notification. It is not linked to any real issue and no recovery follows, so close it by hand once you have seen it arrive.4
Verify the lifecycle
Wait for (or trigger) a project retest and confirm that a new issue opens an alert in Flashduty. Fix the issue, for example by upgrading the dependency, retest, and confirm that the alert recovers.
About the signature
Snyk signs each request in the
X-Hub-Signature header (sha256=<hex HMAC digest>, keyed with the secret you set when creating the webhook). Flashduty does not verify it, so secret can be any random string. The integration_key in the push URL is the only credential; keep it private.
Alert Key
Flashduty builds the Alert Key from the project ID (
project.id) plus the issue ID (id): one alert per issue per project. Issues in newIssues and removedIssues share the same shape and id, so an issue appearing and disappearing land on the same alert.
Changes to the project name, branch, or severity do not change the Alert Key. An issue that repeats for several dependency paths of one project produces a single alert. The same issue in two projects is two alerts.
Status and severity
Flashduty acts only on issues listed in
newIssues and removedIssues. The Snyk docs do not say whether ignoring an issue lists it in removedIssues. Turn on auto-close on timeout for the channel as a safety net so alerts do not stay open indefinitely.
One request processes at most the first 100 issues of newIssues and of removedIssues (sorted by issue ID); issues beyond that create no alert.
Alert labels include the project ID and name, project type, branch, organization, issue ID, package name and versions, CVE, CWE, CVSS score, and the fixed-in version. The importing user’s name and email are not written to the alert.
Troubleshooting
- The create call returns an error: check that
urlis HTTPS, the token has access to the organization, the organization is in a region where Snyk webhooks are available, and the plan includes API access (the Free plan returnsnot entitled for api access) - No alerts arrive: Snyk sends an event only when a project is retested and it is not sent when a project is first imported. Make sure the project’s scan type is Open Source or Container
- An alert does not recover: only issues listed in
removedIssuesrecover their alerts - A test alert appeared: it comes from the
ping/v0event. Close it by hand