Skip to main content

Proxy authentication in Snyk CLI for Windows

Written by

Steve Winton

Jeff McLean

October 6, 2022

0 mins read

Today we’re announcing support for SPNEGO-based Kerberos and NTLM proxy authentication protocol support in Snyk CLI for Windows, with support for other operating systems coming shortly.

What is it?

Proxy authentication is often used to authenticate local network traffic through a centralized proxy, ensuring only authenticated users can access the public internet.

SPNEGO (often pronounced "spenay-go") is an authentication mechanism to negotiate the choice of security technology. It is most prominently used in Microsoft’s HTTP negotiation algorithm, typically surfacing Kerberos or NTLM sub-mechanisms, both of which are used in Active Directory.

Why might I need this?

Within our customers’ enterprise environments, particularly those subject to stringent audit and compliance regulations, it’s a common requirement for all internet-bound network traffic to first authenticate with an internal proxy before being allowed to proceed — for example to communicate successfully with Snyk’s public APIs.

With these additional proxy authentication methods in Snyk CLI, developers in such environments can now run Snyk CLI scans on their code from their development environments — adopting DevSecOps workflows and ensuring the security of their software products well before code changes are released.

How do I use this?

As of Snyk CLI v1.1008.0, the Snyk CLI supports proxy authentication by default. As soon as a proxy is configured, the CLI will determine whether authentication is required and will pick an appropriate mechanism.

Where do I find out more?

Check out our documentation on how to configure a Proxy for the Snyk CLI for more information.

If you’re new to Snyk and want to get started, sign up for a free account.

Get started in capture the flag

Learn how to solve capture the flag challenges by watching our virtual 101 workshop on demand.

Read more

Blog

Frontier models found the vulnerabilities. Only the attacker found the chains.

Static analysis found the flaws, but only live attack testing proved how they could be chained into breaches. A comparison of Evo COS, Claude Security, and Claude Code Security.

feature insights context
Blog

Autonomous Attacks Are Already Here. The Defense Has to Match Their Speed.

Autonomous attackers are shrinking the window for defense. Learn how continuous discovery, remediation, validation, and prevention can help security teams keep pace.

Blog

Why AI Coding Agents Keep Writing Broken Access Control

AI coding agents can produce authorization logic that compiles and passes review while exposing one tenant’s data to another. Learn why broken access control is difficult to detect and how to prevent it.