Documentation

Custom Package Registries

Snyk can be configured to use custom package registries under specific conditions, allowing insight into dependencies that are not hosted in canonical registries.

The Custom Package Registry feature currently supports Artifactory with Maven and is available on the Pro and Enterprise plans. Maven analysis can be configured to mirror all requests through a custom package repository, or you can specify additional repositories to use alongside Maven Central.

Note: Custom Package Registries do not currently work with brokered SCM integrations. If you currently use a brokered SCM integration or need support for other package managers please email contact@snyk.io and we will send you an announcement as soon as support is available.

Setup

If authentication is required to access your custom registry you will need to first configure the Artifactory package repository integration.

To configure the Artifactory integration go to Integrations > Artifactory and click ‘Connect to Artifactory’ and complete the fields - url to your Artifactory, username and password.

Once the integration is set up you can configure Maven settings by navigating to Settings > Languages > Java

You can choose whether to use Artifactory as a mirror or as an additional repository where your artifacts will reside. These settings will be very similar to what you have in ~/.m2/settings.xml.

Mirrors

Choose a value for type, either ‘direct’ or if using authentication ‘integration’. If using direct you will need to complete the url, repository name and what it is a mirror of.

The mirror of value can either be a * to mirror everything or you can type in a value for example “central”

Setting up mirrors with direct configuration

If using the integration, you will need to choose integration type and provide the repository name and mirror of details.

Setting up mirrors with an integration configuration

Repositories

Alternatively you can configure repositories which will be used as additional locations to check for artifacts.