Research
Security News
Malicious npm Package Targets Solana Developers and Hijacks Funds
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
snyk-to-html
Advanced tools
Convert JSON output from `snyk test --json` into a static HTML report
The Snyk JSON to HTML Mapper takes the json outputted from snyk test --json
and creates a local HTML file displaying the vulnerabilities discovered.
First, Install the Snyk JSON to HTML Mapper using npm:
npm install snyk-to-html -g
Alternatively, you can clone the repo and run the script locally using:
npm install
npm run build
node ./dist/index.js
Short | Long | Description |
---|---|---|
-t | --template | Template location for generating the html. Defaults to template/test-report.hbs |
-i | --input | Input path from where to read the json. Defaults to stdin |
-o | --output | Output of the resulting HTML. Example: -o snyk.html . Defaults to stdout |
-s | --summary | Generates an HTML with only the summary, instead of the details report. Defaults to details vulnerability report |
-d | --debug | Runs the CLI in debug mode |
-a | --actionable-remediation | Display actionable remediation info if available |
When in doubt, use snyk-to-html --help
or snyk-to-html -h
.
Snyk JSON to HTML Mapper mapper works with the different Snyk Products. Change the directory to your package's root folder, then use one of the ways below to generate the HTML report, using the appropriate product's command
Directly streaming the results to snyk-to-html:
For Snyk Open Source
Run the following line to create a file called results-opensource.html
:
snyk test --json | snyk-to-html -o results-opensource.html
For Snyk Code
Run the following line to create a file called results-code.html
:
snyk code test --json | snyk-to-html -o results-code.html
For Snyk Infrastructure as Code (IaC) Navigate to the subfolder with the related files.
Run the following line to create a file called results-iac.html
:
snyk iac test --json | snyk-to-html -o results-iac.html
For Snyk Container
Run the following line to create a file called results-container.html
:
snyk container test [image] --json | snyk-to-html -o results-container.html
The following methods/examples will utilize snyk test, however they will also work with the other product commands , as above.
Using a temporary file:
Generate JSON data by running snyk test
and save the output to a file
snyk test --json > results.json
Pass the resulting JSON file to Snyk's JSON to HTML Mapper
snyk-to-html -i results.json -o results.html
Note input files should be valid JSON and use UTF-8 encoding.
If you want a simpler version of the report to be shown, you can pass -s
or --summary
to only
display the summary of the report.
snyk-to-html -i results.json -o results.html -s
Show actionable remediation:
To display the actions you can take to remedy vulnerabilities, pass -a
or --actionable-remediation
.
snyk-to-html -i results.json -o results.html -a
The report orders remediations (upgrades and patches) by the number and severity of vulnerabilities it fixes. Use this to guide when selecting the order to upgrade and patch packages.
Note we currently support remediation advice with the following package managers:
Simply open your new file (results-[type].html
as above) in a browser, and rejoice.
Submit a ticket to Snyk support when you need help with snyk-to-html
or Snyk in general. Note that Snyk support does not actively monitor GitHub Issues on any Snyk development project.
FAQs
Convert JSON output from `snyk test --json` into a static HTML report
The npm package snyk-to-html receives a total of 73,052 weekly downloads. As such, snyk-to-html popularity was classified as popular.
We found that snyk-to-html demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
A malicious npm package targets Solana developers, rerouting funds in 2% of transactions to a hardcoded address.
Security News
Research
Socket researchers have discovered malicious npm packages targeting crypto developers, stealing credentials and wallet data using spyware delivered through typosquats of popular cryptographic libraries.
Security News
Socket's package search now displays weekly downloads for npm packages, helping developers quickly assess popularity and make more informed decisions.