CertSafari
    Snowflake SnowPro Advanced: Security Engineer (SEA-C01)· Lessons

    Domain 5 · Lesson 21/21

    Native App Security Review, Code Requirements and Containers

    Manage security in Snowflake Native Apps.

    10 min read
    4% of exam
    3 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Explain the risks a Native App poses to a consumer account and how NAAAPS scanning and manual review address them
    • Apply the code, dependency and secrets requirements an app must meet before a version can be published
    • Choose INTERNAL or EXTERNAL distribution for development and production application packages
    • Describe the extra review, isolation and approval that apply when a Native App runs Snowpark Container Services

    Key concept

    Reviewed-before-shared — A Native App runs provider code inside the consumer's account. Snowflake therefore requires every app published to consumers to pass a security review of its code, dependencies and (for container apps) images before consumers can install it.

    1.Why apps are scanned: the threat model and NAAAPS

    A Snowflake Native App is code written by a provider that runs inside a consumer's account, next to the consumer's data. Snowflake names four risks that this creates. Data exfiltration: an app copies consumer data out through external functions or logs. Compute abuse: an app runs unauthorized work, such as cryptomining, that the consumer pays for. Ransomware: an app encrypts or corrupts data and demands payment. Privilege escalation: an app tries to gain permissions it was not given.

    The control for these risks is the Native App Anti-Abuse Pipeline Service (NAAAPS). It runs every time a new version or patch is created. NAAAPS copies the app to a dedicated scanning account and scans the app's files. It looks for bugs, anti-patterns and vulnerabilities in the code, scans for malware, and checks the app's dependencies for known vulnerabilities. It then either approves the app automatically or sends it to manual review. A manual review can approve or reject the app. Snowflake sends no notification when an app is rejected, so providers check the review status in Snowsight.

    Checkpoint 1 of 6· Put it in order

    Put the automated security review steps in the order NAAAPS performs them after a provider creates a new version or patch.

    1. 1.Scan the files associated with the app and update the security review status
    2. 2.Copy the app to a dedicated Snowflake account used to scan apps
    3. 3.Auto-approve the app or initiate a manual review

    Sources1

    2.Securing app code, third-party libraries and secrets

    NAAAPS can only scan what is in the package. That is the reason behind the first code rule: an app must not load or run code from outside the application package, except Snowflake-provided libraries. All library dependencies and setup code have to be part of the version itself. A dependency fetched at runtime would bypass the review. All code must also be un-obfuscated, meaning human-readable. As the prediction showed, minified JavaScript is allowed only when it comes with a source map.

    Third-party packages. Any dependency with a critical or high CVE must be updated to a secure version when one exists. Snowflake prioritizes CVEs according to its CVE Evaluation Criteria policy, which applies to every app under security review. As SDLC practice, Snowflake recommends reviewing app code for vulnerabilities before you create a version, and reviewing and updating all third-party libraries at least once a quarter.

    Secrets and data. Apps must not store or require plain-text customer secrets. Secrets and sensitive data should be protected with encryption and access controls. Providers are also responsible for making sure that no personal, sensitive, export-controlled or regulated data ends up in any file in the application package. All Internet traffic from the app must use HTTPS with a valid TLS certificate.

    Checkpoint 2 of 6· Exam question

    A consumer admin has installed a Native App that exposes the application roles `viewer` and `admin`. Analysts must use the app's dashboards, while only the security team may change its configuration. What should the admin do?

    Checkpoint 3 of 6· Check yourself

    A provider wants the app to download its latest Python helper module from the provider's GitHub at startup so that fixes ship without new versions. Why does this violate the code requirements?

    Sources2

    3.Packaging and sharing: INTERNAL vs EXTERNAL distribution

    Because every new version or patch triggers a scan, Snowflake recommends two application packages. The development package has DISTRIBUTION set to INTERNAL. It is not distributed to external consumers or sent to Snowflake for scanning, so developers can iterate without triggering a review each time. The production package has DISTRIBUTION set to EXTERNAL. It is the package that goes to Snowflake for scanning and approval and then to consumers. Only versions that have passed the provider's own security review should be added to it.

    The two recommended application packages
    PackageDISTRIBUTIONScanned by Snowflake?Purpose
    DevelopmentINTERNALNoRapid iteration and testing
    ProductionEXTERNALYes, then released to consumersPublishing approved versions

    Setting a package up for external sharing automatically shares the app's code with Snowflake for scanning. That scan runs in a mapped region. Most AWS regions are scanned in the same region. Azure regions are grouped into three scanning regions. Listed GCP regions are scanned in AWS US West (Oregon). Apps can be published as private listings or on Snowflake Marketplace, and Marketplace adds its own listing guidelines. Every listing must also tell consumers about all app functionality, every Internet endpoint the app connects to, every external function, and any consumer data the app logs, collects or stores.

    Checkpoint 4 of 6· Check yourself

    A team wants to test dozens of builds a day without each one going through Snowflake's security scan. What should they do?

    Sources21

    4.Implications of running a Native App in Snowpark Container Services

    An app that ships container images has a larger attack surface, and Snowflake responds in four ways. Image scanning: tools scan the container images for known vulnerabilities and violations of security best practices. Network isolation: each app with containers runs in its own isolated network environment. Snowflake monitors and filters egress to detect suspicious traffic, and the provider must declare every external endpoint in the manifest, which is itself reviewed. Scoped data access: the app can reach only the data and resources it has been granted. Consumer data is protected by encryption in transit and at rest and by fine-grained access controls.

    Provider approval: before a provider can create a public or private listing for an app with containers, the Snowflake Product Security team must approve that provider. If the provider has not been approved and sets DISTRIBUTION=EXTERNAL on a package with containers, Snowflake returns error 093197. The provider then submits a security questionnaire about its security practices and compliance readiness. Only after approval does the app go through the automated scan, which combines the normal app scan with a scan of the container images. Scan time grows with the number and size of images:

    Approximate scan time for apps with containers (guidance only, not an SLA)
    App sizeApproximate time to complete scan
    Five images or fewer / smaller than 40 GBLess than 8 hours
    Ten images or fewer / smaller than 70 GBLess than 24 hours
    Ten images or more / larger than 70 GB2 business days or more

    Snowflake also lists extra best practices for container apps. Limit external dependencies to reduce supply-chain risk. Harden images with minimal base images and remove unnecessary packages. Encrypt communication between containers and to external systems. Log container activity and data access. Patch images regularly. Request only the privileges the app needs.

    Checkpoint 5 of 6· Exam question

    A provider wants to publish a Native App on the Snowflake Marketplace for consumers outside its organization. Which sequence correctly gets a new version through the mandatory security review?

    Checkpoint 6 of 6· Check yourself

    Which statement about a Native App with containers is supported by Snowflake's documentation?

    Sources3

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.If my app is rejected in manual review, Snowflake will email me.Why is that wrong?

      Snowflake does not notify the provider of a rejection. Providers must check the review status in Snowsight.

      Covered in Why apps are scanned: the threat model and NAAAPS

    2. 2.Any minified JavaScript in an app counts as obfuscation and causes rejection.Why is that wrong?

      Minified JavaScript is acceptable when a source map that recovers the un-minified code is included.

      Covered in Securing app code, third-party libraries and secrets

    3. 3.An app with containers can be published as soon as its automated scan passes.Why is that wrong?

      The provider must first be approved by Snowflake Product Security through a security questionnaire before it can list an app with containers.

      Covered in Implications of running a Native App in Snowpark Container Services

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “Data exfiltration: Malicious apps could copy consumer data to external functions or logs.”
      ↩︎ Why apps are scanned: the threat model and NAAAPS
      “This automated security review occurs when a new version or patch of an app is created.”
      ↩︎ Why apps are scanned: the threat model and NAAAPS
      “When configuring a Snowflake Native App to be shared externally, providers automatically share the code in app with Snowflake for scanning.”
      ↩︎ Packaging and sharing: INTERNAL vs EXTERNAL distribution
      “All apps that are published to consumers must pass this security review.”
      ↩︎ Key concept
      “Snowflake does not send a notification if an app is rejected.”
      ↩︎ Exam trap 1
      “Copies the app to a dedicated Snowflake account used to scan apps.”
      ↩︎ Checkpoint
    2. 2.
      “All dependencies or libraries with critical or high common vulnerabilities and exposures (CVE) must be updated to a secure version, if available.”
      ↩︎ Securing app code, third-party libraries and secrets
      “Apps must not store or require any plain text customer secrets.”
      ↩︎ Securing app code, third-party libraries and secrets
      “Review and update all third-party libraries in the app at least once a quarter.”
      ↩︎ Securing app code, third-party libraries and secrets
      “The production application package should have its DISTRIBUTION property set to EXTERNAL.”
      ↩︎ Packaging and sharing: INTERNAL vs EXTERNAL distribution
      “it must include a corresponding source map file that can be used to recover the un-minified code”
      ↩︎ Exam trap 2
      “it must include a corresponding source map file that can be used to recover the un-minified code”
      ↩︎ Prediction
      “Your app must not load or execute any code from outside the application package except Snowflake-provided libraries.”
      ↩︎ Checkpoint
      “It should have its DISTRIBUTION property set to INTERNAL.”
      ↩︎ Checkpoint
    3. 3.
      “Each app with containers runs in its own isolated network environment, with controlled access to external systems and services.”
      ↩︎ Implications of running a Native App in Snowpark Container Services
      “This scan includes a normal app security scan and a scan of the container images included in the app.”
      ↩︎ Implications of running a Native App in Snowpark Container Services
      “they must be approved by the Snowflake Product Security team”
      ↩︎ Exam trap 3
      “App providers are required to explicitly declare all external endpoints in the application manifest, which undergoes a security review.”
      ↩︎ Checkpoint

    Continue to page 2 of 2

    Native App Permissions, Application Roles and Consumer OAuth

    Spotted a mistake, or was something unclear? Tell us.