Skip to content

Update dependency snyk to v1.1297.3 [SECURITY]#1085

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-snyk-vulnerability
Open

Update dependency snyk to v1.1297.3 [SECURITY]#1085
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-snyk-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate Bot commented Nov 20, 2022

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
snyk 1.299.01.1297.3 age confidence

Snyk CLI affected by Command Injection vulnerability

CVE-2022-40764 / GHSA-hpqj-7cj6-hfj8

More information

Details

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.

Severity

  • CVSS Score: 7.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Snyk plugins vulnerable to Command Injection

CVE-2022-22984 / GHSA-4x6g-3cmx-w76r

More information

Details

The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @​snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the package @​snyk/snyk-hex-plugin before 1.1.6 are vulnerable to Command Injection due to an incomplete fix for CVE-2022-40764. A successful exploit allows attackers to run arbitrary commands on the host system where the Snyk CLI is installed by passing in crafted command line flags. In order to exploit this vulnerability, a user would have to execute the snyk test command on untrusted files. In most cases, an attacker positioned to control the command line arguments to the Snyk CLI would already be positioned to execute arbitrary commands. However, this could be abused in specific scenarios, such as continuous integration pipelines, where developers can control the arguments passed to the Snyk CLI to leverage this component as part of a wider attack against an integration/build pipeline. This issue has been addressed in the latest Snyk Docker images available at https://hub.docker.com/r/snyk/snyk as of 2022-11-29. Images downloaded and built prior to that date should be updated. The issue has also been addressed in the Snyk TeamCity CI/CD plugin as of version v20221130.093605.

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


snyk Code Injection vulnerability

CVE-2022-24441 / GHSA-4vrv-93c7-m92j

More information

Details

The package snyk before 1.1064.0 is vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges of the application. This vulnerability may be triggered when running the the CLI tool directly, or when running a scan with one of the IDE plugins that invoke the Snyk CLI. Successful exploitation of this issue would likely require some level of social engineering - to coerce an untrusted project to be downloaded and analyzed via the Snyk CLI or opened in an IDE where a Snyk IDE plugin is installed and enabled. Additionally, if the IDE has a Trust feature then the target folder must be marked as ‘trusted’ in order to be vulnerable.

NOTE: This issue is independent of the one reported in CVE-2022-40764, and upgrading to a fixed version for this addresses that issue as well.

The affected IDE plugins and versions are:

  • VS Code - Affected: <=1.8.0, Fixed: 1.9.0
  • IntelliJ - Affected: <=2.4.47, Fixed: 2.4.48
  • Visual Studio - Affected: <=1.1.30, Fixed: 1.1.31
  • Eclipse - Affected: <=v20221115.132308, Fixed: All subsequent versions
  • Language Server - Affected: <=v20221109.114426, Fixed: All subsequent versions

Severity

  • CVSS Score: 8.8 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode

CVE-2025-6624 / GHSA-6hwc-9h8r-3vmf

More information

Details

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in DEBUG or DEBUG/TRACE mode.

The issue affects the following Snyk commands:

  1. When snyk container test or snyk container monitor commands are run against a container registry, with debug mode enabled, the container registry credentials may be written into the local Snyk CLI debug log. This only happens with credentials specified in environment variables (SNYK_REGISTRY_USERNAME and SNYK_REGISTRY_PASSWORD), or in the CLI (--password/-p and --username/-u).

  2. When snyk auth command is executed with debug mode enabled AND the log level is set to TRACE, the Snyk access / refresh credential tokens used to connect the CLI to Snyk may be written into the local CLI debug logs.

  3. When snyk iac test is executed with a Remote IAC Custom rules bundle, debug mode enabled, AND the log level is set to TRACE, the docker registry token may be written into the local CLI debug logs.

Severity

  • CVSS Score: 1.2 / 10 (Low)
  • Vector String: CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

snyk/snyk (snyk)

v1.1297.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • logging: Improves the sanitization of credentials in local debug logs. (38322f3)

v1.1297.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • logging: Improves the sanitization of credentials in local debug logs. (e054455)
  • language-server: IDE Connectivity for Proxy Users: Fixes an issue where IDE plugins could fail to connect when operating behind an NTLM proxy.
  • language-server: Snyk Code Local Engine Fix: Addresses a regression that prevented the Snyk Code Local Engine (SCLE) from functioning correctly within the IDEs.

v1.1297.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • test: Rollbacked a regression introduced by a change in gradle module resolution in version 1.1297.0 (7991133)

v1.1297.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features
  • container: Support scanning container images from tar files without specifying a type (58b0861)
  • iac: Improve IaC deployment to avoid on the fly downloads (5108f58)
  • sbom: Introduce sbom monitor command (24e96c3)
  • test: Improve gradle module resolution (7991133)
  • language-server: Introduce explanation of AI fixes in IDEs (74fa322)
Bug Fixes
  • container: Fix issue when scanning invalid node manifest files (ceb8020)
  • code: Fix hash mismatches for files containing non-UTF-8 content (33d33e9)
  • iac: Ensure to use the correct org id when sharing results for v2 (1c4094a)
  • iac: Ensure to use target-name (2201f0a)
  • sbom: Fix issues when generating sboms based on NuGet .sln (80c43d9)
  • test: Fix issues when scanning gradle projects on Windows (11586cc)
  • test: Improve error messages when using fail-fast, all-projects and json (a396bd6)
  • test: Fix yarn 2 out of sync issues (18aee45)
  • test: Fix pnpm out of sync issue for duplicated peer and dev dependencies (2581e16)
  • test: Ensure internal dependencies are represented correctly when normalizing Gradle dependencies (c7e2713)
  • test: Fix testing composer-based PHP projects (39e3379)
  • language-server: Fix and improve issue filtering in IDEs (a474d67)
  • language-server: Fix unmanaged C/C++ scans with '—unmanaged' flag in additional parameters (01f53e3)
  • language-server: Fix applying Snyk Code AI fixes on the wrong lines (01f53e3)

v1.1296.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • mcp: Add experimental Model Context Protocol server for agentic workflow support (3b5f494)
Bug Fixes
  • general: Fix OAuth authentication issues (b2684db)
  • code: Write JSON/SARIF files when nested directories do not exist (faca897)
  • test: Clearer error messages when testing multiple projects with fail-fast (a396bd6)

v1.1296.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • test: Add poetry v2 support (49c6652)
  • code: Fix backward compatibility issue in sarif driver name (5ef6442)
  • iac: Fix iac test network issues (815ed82)
  • language-server: Increase authentication resilience (07fc381)
  • language-server: Avoid that the trust dialog blocks the application. (07fc381)
  • language-server: Fix duplicate Open Source Issues appearing only in a single IDE tree node, despite occurring in multiple files. (07fc381)
  • dependency: Upgrade golang.org/x/net to address CVE-2025-22870 (7edd450)

v1.1296.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • general: Improved error logging and handling
Features
  • container: add support for --exclude-node-modules option (4756f27)
  • container: adds kaniko support (bfb69c8)
  • general: display a unique interactionID alongside each error (960a71c)
  • test: python support for local wheel files specifiers (42675eb)
  • test: dep-graph json file output (90f24ec)
  • test: print legacy tree with json file output (b256937)
  • test: display all applicable maven unmanaged identities (ebf6ba1)
  • code: enable v1 fingerprints in code sarif output (00644af)
  • test: Add 'pkgIdProvenance' labels to dependency graph nodes when the package identity has been changed from what has been discovered in the manifest files (4d529b3)
  • test: added Python support for sys_platform (1aa1565)
  • language-server AI fix explain (26d118f)
  • language-server enable calling mcp commands via ls commands (6f80a03)
  • language-server add scan source to metrics (6f80a03)
  • language-server add mcp server, refactoring (6f80a03)
  • language-server added a new code action and code lens for showDocument (8e7ab06)
  • language-server add Option for Pre-Scan command, fix auth race (64920ac)
  • language-server add ideStyle variable to static html (0a05e66)
  • language-server intiial commit of shared html for scan summary panel (0a05e66)
  • language-server send scan summary and scan base & working directory concurrently (1908a08)
  • language-server store folder config outside of git repo, add reference folder (50d0770)
  • language-server send initial summary panel notification (50d0770)
  • language-server add a new $/snyk.scanSummary notificiation (fc80c9c)
  • language-server support maven pom hierarchies for highlighting & fixes (e5924fc)
  • language-server Sending a user event when fixing inside the editor (e5924fc)
  • language-server Sending IDE+extension versions to autofix (a18975a)
Bug Fixes
  • container: add container test doc info for --exclude-node-modules (2faf2d1)
  • test: fix dotnet UTF-16LE support for target framework (e90075a)
  • test: reduce false positives when scanning improved dotnet projects (c21625a)
  • test: use --strict-out-of-sync when set to false with pnpm for top level dependencies (8d5b71a)
  • test: fix OutOfSync errors in pnpm for download urls (b6e4ea0)
  • test: fix OutOfSync errors in pnpm git protocol dependencies (5c8dc34)
  • code: Don't write sarif files when no results are found (5a15113)
  • code: Support single file test for golang native implementation (d7881f1)
  • sbom: mavenAggregateProject with Dverbose or sbom (e88cf71)
  • iac: Updates the user messages for snyk iac test --report for IaC V2 (1c9b3b3)
  • language-server check folder trust before opening/changing/saving file (26d118f)
  • language-server new issue summary totals (6f80a03)
  • language-server add correct lesson url for license issues (6f80a03)
  • language-server issues with non-UTF-8 encoded files in Snyk Code (8e7ab06)
  • language-server ignore first dataflow element for oss fingerprint (64920ac)
  • language-server use workdir folderConfig for ref Scan (64920ac)
  • language-server test bundle add size property (0a05e66)
  • language-server normalize path for file filter and reduce memory footprint (0a05e66)
  • language-server add ideScript to Summary html (0a05e66)
  • language-server add css variables and headers (0a05e66)
  • language-server panic in range_finder (50d0770)
  • language-server fix issue metadata used for hashing (fc80c9c)
  • language-server use diff without enricher for delta (b213b58)
  • language-server move issue view option filtering to the LS to not display ignored diagnostics in editor (b213b58)
  • language-server add api version query to explain API URL (b213b58)

v1.1295.4

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

v1.1295.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • security: Upgrades dependencies to address CVE-2025-21614
  • language-server: Improved memory usage when executing code scans on large projects
  • language-server: Fix incorrect filtering of files when executing code scans which could fail the analysis
  • language-server: Fix random unexpected logouts when using OAuth2 authentication

v1.1295.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • general: revert dependencies upgrade which introduced a regression on a number of Linux installations

v1.1295.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • security: Upgrades goproxy to 1.5 to address a high severity vulnerability
  • security: Upgrades dependencies in IaC plugin to address CVE-2025-21614

v1.1295.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features
  • iac: include evidence field in json output [IAC-3161] (9487a08)
  • auth: auto detect API Url during OAuth authentication (6884511)
Bug Fixes
  • test: support verbose gradle graphs for sbom generation (600ef50)
  • general: prevent snyk-policy lib from interrupting stdout to ensure valid --json --sarif output (469edf5)
  • general: improved error messages around network requests (f6fc5f7)
  • general: only read SNYK_ prefixed env vars (5bfcbe8)
  • instrumentation: add default oss product for monitor as well (83cabc3)
  • container: optional dependencies are properly connected in the dep-graph (3205e66)
  • container: package-lock v3 missing sub-dependencies 94c9b7f)
  • container: support --exclude-app-vulns with oauth (73a75fa)
  • monitor: use error catalog messages for monitor commands (4e58601)
  • iac: extra error handling and debugging [IAC-3138] (7fbae0f)
  • iac: snyk-iac-test security update [IAC-3171] (fac22bb)
  • iac: update snyk-iac-parsers version [IAC-3138] (5326d9d)
  • iac: use proxy aware snyk-iac-test [INC-1647] (d5d1e2e)
  • test: do not treat warnings as errors on restore (d0113eb)
  • test:fix mismatch/off-by-one on unmanagedDependencyCount in the analytics logs UNIFY-340 (75d8e6d)
  • test: update snyk-nodejs-plugin to fix micromatch vuln (766bd1d)
  • test: upgrade mvn-plugin to handle jar scanning sha-not-found error (060380a)
  • test: fix runtime versions overwriting nuget versions (5e715cf)
  • instrumentation: stop sending CLI args in analytics (6d183fb)
  • policy update policy library to fix valid json output (0bc0aed)

v1.1294.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

v1.1294.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • container: ignore npm/yarn default cache directories
  • container: fix: avoid possible unhandled promise rejections

v1.1294.1

Compare Source

Bug Fixes
  • container: unable to process RedHat images when the “content_sets” attribute was missing in the redhat-content-manifests file. (snyk/snyk-docker-plugin#615)
  • container: skip optional dependencies when testing Python projects to prevent "too many vulnerable paths for conversion to legacy test output" error (snyk/snyk-docker-plugin#614)
  • container, test, monitor prevents "Invalid JSON" being produced when debugging is enabled and policies are being applied. (snyk/cli#5583)

v1.1294.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • CycloneDX 1.6 SBOM support This new version now supports generating CycloneDX 1.6 SBOMs using the snyk sbom command, providing you with more comprehensive and detailed information about your software components and their dependencies. Read more about the CycloneDX version announcement here.
  • Improved CLI monitoring of large Cocoapods projects When doing a snyk monitor on very large Cocoapods applications, the CLI sometimes returned an Invalid String OOM error and the operation would fail. Although this error was rare, we have fixed it so large Cocoapods applications can now be monitored successfully.
  • Fix for security issue The Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted (PHP|Gradle) project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current working directory name. Snyk always recommends not scanning untrusted projects.
Features
  • sbom: add CycloneDX 1.6 SBOM support (1330fc2)
  • deployment: Deploy alpine arm64 binaries (9daace4)
  • monitor: enable cocoapods to send graphs for cli monitor (ca56c69)
  • iac: pass allow analytics flag to snyk-iac-test [IAC-3017] (b12d3ac)
Bug Fixes
  • all: restore cert file if it was externally removed (ef1547f)
  • auth: missing auth issue with oauth (57ae95c)
  • iac: upgrade iac custom rules ext to address vulns [IAC-3065] (d6cc509)
  • iac: upgrade snyk-iac-test to v0.55.1 [IAC-2940] (0dadc90)
  • monitor: add normalize help for deriving target files [CLI-448] (82efb50)
  • sbom: include CVE in JSON output of sbom test command (a543179)
  • sbom: add missing option --gradle-normalize-deps to SBOM command (151f63d)
  • test: default limit to max vulnerable paths per vuln, add override option --max-vulnerable-paths (302d7ac)
  • test: do not show test deps for Dverbose mvn with dependencyManagement (67e0de9)
  • test: fixed support for pnpm alias packages (d506de1)
  • test: point snyk policy out urls to snyk.io (28509a3)
  • test: scan non publishable projects on improved net (a6c0e67)
  • test: scan nuget with PublishSingleFile turned on (2c74298)
  • dependencies: update snyk-nodejs-plugin to fix micromatch vuln (baef934)
  • dependencies: address security vulnerability in snyk-php-plugin CVE-2024-48963 (7798d13)
  • dependencies: address security vulnerability in snyk-gradle-plugin CVE-2024-48964 (c614284)
  • dependencies: upgrade go-getter to 1.7.5 (970de96)
  • dependencies: upgrade iac extension and snyk-iac-test (9134c05)
  • dependencies: upgrade slack/webhook to 7.0.3 (8ab4433)

v1.1293.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • Starting with this version, Snyk cli binaries will be distributed via downloads.snyk.io instead of static.snyk.io. This includes intallation from npm.

v1.1293.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • Starting with this version, Snyk cli binaries will be distributed via downloads.snyk.io instead of static.snyk.io. This includes intallation from npm, homebrew and scoop as well as many of the CI/CD integrations.
Features
  • sbom: add support for license issues in sbom test (6948668)
  • auth: Use OAuth2 as default authentication mechanism (35949c4)
  • config: Introduce config environment command (0d8dd2b)
  • container: When docker is not installed, platform parameter is now supported (64b405d)
Bug Fixes
  • auth: align auth failure error messages for oauth (e3bfec3)
  • auth: ensure environment variable precedence for auth tokens (24417d6)
  • test: fix a bug related to multi-project .NET folder structures (755a38f)
  • test: multiple pnpm workspace improvements (da5c14f)
  • test: fixes a bug regarding Snyk attempting to get the dependencies from the wrong nuget *.deps.json file.(2e17434)
  • test: support for pipenv with python 3.12 (09df3bc)
  • test: support multi-part comparison for python pip versions. (b625eb9)
  • container: container monitor with --json now outputs valid json(039c9bd)
  • container: support hashing large .jar files (6f82231)
  • sbom: fix issues in JSON output of sbom test command, include CWE values on CWE property (#​5331) (99773c3)
  • sbom: include all detected dep-graphs of a container image (ea43977)
  • iac: fixed an issue where the resource path was missing for certain Terraform resources. IAC-3015
  • general: map previously unhandled exit codes to exit code 2 (9fde4fe)
  • general: use entitlements when signing bundled macos binaries (bebc59c)

v1.1292.4

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Complete changelog

Bug Fixes
  • deployment: Rollback of digital signature for the bundled macOS binary (#​5416)

v1.1292.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Complete changelog

Bug Fixes
  • deployment: Add digital signature for the bundled macOS binary
    (#​5404)

v1.1292.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Complete changelog

Bug Fixes
  • container test: Improve the accuracy of identifying npm projects within docker images by removing the explicit folder ignore rules
    (#​5384)
  • container test: Pass platform parameter when pulling an image from a container registry (#​5360)

v1.1292.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Complete changelog

Bug Fixes
  • test,monitor: fix improper permission error handling when accessing 'enablePnpmCli' feature flag

v1.1292.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News

This Snyk CLI release delivers an assortment of bug fixes and improvements.

  • We've added support for pnpm, giving you more flexibility in your project setup.
  • You can now scan npm/yarn projects even without lockfiles, ensuring comprehensive vulnerability detection regardless of your dependency management approach.
  • We're committed to strengthening security. This release includes redaction of additional sensitive data in debug logs, minimizing potential risks.

Complete changelog

Features
  • test: Added pnpm support under 'enablePnpmCli' feature flag (#​5181) (46769cc)
  • test: Support scan of npm/yarn projects without lockfiles (e2d77a9)
  • monitor: Set target-reference in the monitor request (51ed8f5)
  • code: Centrally check if code test is enabled (#​5239) (e5a00e2)
  • sbom: Improve depgraph for Maven projects (fbb33d7)
  • sbom: Use RFC 3339 for all timestamps in sbom test result (#​5204) (91bf191)
  • language-server: Add --all-projects flag scans by default#​5247k/snyk/issues/5247)) (fdcf30e)
  • language-server: Enable incremental scanning#​5291k/snyk/issues/5291)) (d198685)
  • language-server: Add support for IDE themes (c1c4d08)
  • language-server: Consistent styling across intellij and vscode (#​5282) (9aa6f76)
  • logging: Redact additional types of sensitive data from debug logs (#​5254) (056cdab)
Bug Fixes
  • auth: Autodetect IDE usage and fallback to API token based authentication (#​5241) (4c795e0)
  • iac: Upgrade iac custom rules to address Vulnerabilities#​5191yk/snyk/issues/5191)) (453db24)
  • language-server: Caching problem when no vulnerabilities in the IDE (#​5223) (89c9491)
  • language-server: Remove incorrect /v1 path (#​5214) (cf16470)
  • dependencies: Update dependencies to reduce vulnerabilities (#​5131) (4c7cb3c)
  • sbom: sbom test output padding (e3b7cac)
  • sbom: Fix container purl generation for apt and rpm (#​5207) (fa9d512)
  • sbom: Retain error code during SBOM generation (#​5202) (5e98aaa)
  • test: support cyclic dependencies in maven with dverbose (#​5208) (fb24c02)
  • test: Add tool version and informationUri to sarif output ([#​5203](

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 612ed33 to 1aeb710 Compare March 17, 2023 05:50
@qlty-cloud-legacy
Copy link
Copy Markdown

qlty-cloud-legacy Bot commented Mar 17, 2023

Code Climate has analyzed commit b5e2dcb and detected 0 issues on this pull request.

View more on Code Climate.

@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 1aeb710 to 9e35562 Compare March 24, 2023 23:58
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 9e35562 to dbb3143 Compare May 28, 2023 10:51
@renovate renovate Bot changed the title Update dependency snyk to v1.996.0 [SECURITY] Update dependency snyk to v1.1064.0 [SECURITY] May 28, 2023
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from dbb3143 to fa6bc11 Compare June 4, 2023 14:33
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from a466a35 to 0cd1382 Compare June 18, 2023 09:50
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 0cd1382 to 28d9aa2 Compare June 29, 2023 10:47
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from ec3bd35 to d44b287 Compare July 9, 2023 11:16
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 2e42400 to ecfdbf5 Compare July 19, 2023 09:08
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from c1e3737 to 23d44c7 Compare August 1, 2023 14:58
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 7f8f23b to 694fd22 Compare August 10, 2023 21:17
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 497e33d to dbdb344 Compare August 27, 2023 08:42
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from dbdb344 to a2001a8 Compare September 19, 2023 11:33
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 3c353a0 to d774638 Compare September 28, 2023 14:45
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from a63e309 to a7098da Compare October 15, 2023 16:19
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from a7098da to d40fd80 Compare October 23, 2023 13:16
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from d40fd80 to 2c5d223 Compare November 6, 2023 06:32
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 2c5d223 to 4de2e05 Compare November 16, 2023 10:14
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 4de2e05 to 8ea091b Compare December 3, 2023 13:17
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 47649ab to 9a49b37 Compare February 4, 2024 11:30
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 52979a9 to 2fc28bd Compare October 17, 2024 02:15
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 2fc28bd to 7030b13 Compare December 2, 2024 09:52
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from fbc0e06 to b0944bb Compare January 30, 2025 17:03
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from b0944bb to 8729fc1 Compare February 9, 2025 13:47
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 8729fc1 to f1931f1 Compare March 3, 2025 11:51
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from f1931f1 to 59914d4 Compare March 13, 2025 19:49
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 59914d4 to 0b2e43b Compare April 1, 2025 13:56
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 0b2e43b to f94bb7f Compare April 24, 2025 10:48
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from f94bb7f to 40a6755 Compare May 19, 2025 17:53
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 40a6755 to d4e2929 Compare June 22, 2025 14:01
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from d4e2929 to e38c4b2 Compare June 30, 2025 16:43
@renovate renovate Bot changed the title Update dependency snyk to v1.1064.0 [SECURITY] Update dependency snyk to v1.1297.3 [SECURITY] Jun 30, 2025
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from e38c4b2 to f52c148 Compare July 2, 2025 13:33
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from f52c148 to b5e2dcb Compare July 12, 2025 16:05
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from b5e2dcb to 1a5e40e Compare August 10, 2025 13:33
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 1a5e40e to 5001c32 Compare August 19, 2025 13:08
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 5001c32 to 150eec1 Compare September 25, 2025 18:14
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 150eec1 to 997f29d Compare October 22, 2025 00:07
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 997f29d to 1ec0e74 Compare November 10, 2025 19:09
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 1ec0e74 to 3a5454d Compare December 3, 2025 18:49
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 3a5454d to 402221b Compare December 31, 2025 17:50
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch 2 times, most recently from 76c99bf to 7f63830 Compare January 23, 2026 17:40
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 7f63830 to 947f6cb Compare February 12, 2026 17:46
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 947f6cb to 9eb5c2a Compare March 5, 2026 14:34
@renovate renovate Bot force-pushed the renovate/npm-snyk-vulnerability branch from 9eb5c2a to 93fce5b Compare April 1, 2026 17:33
@renovate renovate Bot changed the title Update dependency snyk to v1.1297.3 [SECURITY] Update dependency snyk to v1.1297.3 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants