Outage in Snyk

PNPM project testing and import degraded for SCM scans in regional environments

Minor
December 18, 2025 - Started 13 days ago
Official incident page

Incident Report

We have detected an issue that is causing SCM scans of PNPM projects to be mis-attributed to NPM or Yarn. This is only occurring in the regional hosted environments (customers that login on sites other than app.snyk.io) Symptoms: * PNPM projects may be detected as NPM projects, or display import errors due to missing yarn.lock files. * Customers using set-and-forget may notice that projects previously detected as PNPM are deactivated and new NPM projects are created. * Customers may notice a change in dependency or vulnerability reports for these projects. This does not affect customers on app.snyk.io This does not affect customers using Snyk CLI to scan pnpm projects, where the PNPM option is enabled in snyk preview. We will update with further information as it becomes available

Need to monitor Snyk outages?

One place to monitor all your cloud vendors. Get instant alerts when an outage is detected.

Latest Updates ( sorted recent to last )
MONITORING 12 days ago - at 12/18/2025 10:38PM

We have applied a fix for this issue, and projects are now testing and importing correctly.
* Customers who have been affected are advised to import the affected repos again to ensure that projects are correctly identified, and any projects that were not able to import due to this incident are imported correctly. There is no need to delete existing projects.

IDENTIFIED 12 days ago - at 12/18/2025 03:44PM

Our Engineers have identified the root cause and are now working on a solution.

We'll keep you updated with our progress.

INVESTIGATING 13 days ago - at 12/18/2025 07:11AM

We have detected an issue that is causing SCM scans of PNPM projects to be mis-attributed to NPM or Yarn.
This is only occurring in the regional hosted environments (customers that login on sites other than app.snyk.io)
Symptoms:
* PNPM projects may be detected as NPM projects, or display import errors due to missing yarn.lock files.
* Customers using set-and-forget may notice that projects previously detected as PNPM are deactivated and new NPM projects are created.
* Customers may notice a change in dependency or vulnerability reports for these projects.
This does not affect customers on app.snyk.io
This does not affect customers using Snyk CLI to scan pnpm projects, where the PNPM option is enabled in snyk preview.

We will update with further information as it becomes available

Status Aggregator for All Your Third-Party Services

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 5010 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook