OpenShift-ci added support for snyk scans on PRs: https://docs.ci.openshift.org/docs/how-tos/add-security-scanning/. We should add a snyk scan check on PRs and/or releases. The check would not be blocking, for now (at least until we have figured out if it's actually valuable)