๐จ [security] [thunksparallel] Update snyk 1.1064.0 โ 1.1298.0 (minor) #4994
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
๐จ Your current dependencies have known security vulnerabilities ๐จ
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
โณ๏ธ snyk (1.1064.0 โ 1.1298.0) ยท Repo
Security Advisories ๐จ
๐จ Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode
Release Notes
Too many releases to show here. View the full release notes.
Commits
See the full diff on Github. The new version differs by 72 commits:
Merge pull request #6042 from snyk/tmp/150725-rc
docs: update release notes
Merge pull request #6041 from snyk/fix/CLI-1004_handle_logging_timestamp_formatting_errors
fix: handle errors when formatting log timestamps
Merge pull request #6034 from snyk/chore/IAC-3308/add-usage-error
chore: added test limit reached error for IaC [IAC-3308]
Merge pull request #6032 from snyk/fix/IAC-3375/update-iac-cli-extension
fix(iac): fix status code checks [IAC-3375]
Merge pull request #6039 from snyk/feat/OSM-2667/maven-dverbose-exhaustive-deps-versions
chore: maven dverbose returns all versions of deps under ff
Merge pull request #6038 from snyk/feat/automatic-upgrade-of-ls
feat: automatic integration of language server 41e841b099e2808f964fc6312c0bf887dd77de5d
Merge pull request #6037 from snyk/tmp/1752481441-release-candidate
Merge remote-tracking branch 'origin/release-candidate' into tmp/1752481441-release-candidate
docs: update release notes
Merge pull request #6024 from snyk/feat/automatic-upgrade-of-ls
feat: automatic integration of language server 3a7ebaa41ec0b4e31d65b558b90a84909e3a7696
Merge pull request #5985 from snyk/fix/support-sarif-json-output-files-combination
fix(code): Fix ichanged sarif and json file output handling
Merge pull request #6031 from snyk/chore/cli-946_remove-snyk-fix-cta
chore: remove snyk fix call-to-action
Merge pull request #6026 from snyk/docs/automatic-gitbook-update-readme-main
docs: synchronizing README from snyk/user-docs
Merge pull request #6025 from snyk/docs/automatic-gitbook-update-cli-help-main
docs: synchronizing help from snyk/user-docs
Merge pull request #6023 from snyk/chore/cli-958_updatePublicDocsSync
chore(docs): update public docs paths for sync workflows
Merge pull request #6022 from snyk/feat/CLI-957_redact_more_auth_types
fix(logging): redact negotiate in debug logs
Merge pull request #6016 from snyk/feat/bump-snyk-docker-plugin
fix: bumped snyk-docker-plugin to v8.3.1 which introduces:
Merge pull request #6020 from snyk/feat/automatic-upgrade-of-ls
feat: automatic integration of language server 32d15f8b765abae260c5c347cf2415de008c73f0
Merge pull request #6019 from snyk/fix/bump-nodejs-lockfile-parser-version
fix: bump nodejs parser to handle manual aliases on indirct deps.
Merge pull request #6018 from snyk/fix/snyk-gradle-plugin-performance-improvements
fix: Performance improvements in `snyk-gradle-plugin`
Merge pull request #6017 from snyk/feat/snyk-gradle-plugin-bump
feat: Better gradle internal project depedencies support
Merge pull request #5998 from snyk/feat/automatic-upgrade-of-ls
feat: automatic integration of language server c3703ce6473d7d1373505994777af9b51d7d7493
Merge pull request #5973 from snyk/chore/CLI-856_invokewith
chore: Invoke engine with instrumentation collector
Merge pull request #6007 from snyk/dotkas/CLI-969/add-debug-log-warning-message
chore: adding warning message to debug logs
Merge pull request #5988 from snyk/feat/add-support-for-dotnet-without-publish-algorithm
Merge branch 'main' into feat/add-support-for-dotnet-without-publish-algorithm
Merge pull request #6014 from snyk/docs/automatic-gitbook-update-cli-help-main
docs: synchronizing help from snyk/user-docs
Merge pull request #6013 from snyk/docs/automatic-gitbook-update-readme-main
docs: synchronizing README from snyk/user-docs
Merge pull request #6011 from snyk/dotkas/docs-update-yet-again
Merge branch 'main' into feat/add-support-for-dotnet-without-publish-algorithm
chore: fixing more docs issues
Merge pull request #6002 from snyk/dotkas/docs-update-yet-again
chore: fixing more docs issues
Merge pull request #5996 from snyk/dotkas/fix-more-docs-automation
chore: updating the order of commit/pr in the docs sync script
feat: [OSM-2832] add support for dotnet without publish
Merge pull request #5997 from snyk/chore/update_main_1.1297.3
chore: sync with 1.1297.3 release and update gaf
Merge pull request #5982 from snyk/fix/unspecified-python-requirement-would-fails-when-dir-with-same-name-present
fix: Fix handling of python requirement if dir with same name exists
Merge pull request #5914 from snyk/feat/support-sle15.2+
feat: container support for rpm packages scanning in SLE15.2+ images
Merge pull request #5995 from snyk/dotkas/chore-fix-build-deps
chore: wait for testing go until prepare build is done
Merge pull request #5980 from snyk/dotkas/CLI-936/optimize-test-pipeline-for-docs
chore: adding an ignore step to the docs update pipelines to avoid over-testing
Merge pull request #5991 from snyk/feat/automatic-upgrade-of-ls
Merge pull request #5993 from snyk/release/1.1297
feat: automatic integration of language server b2101136a81e709ed222ee5fc72e48e89d4f1a0c
๐ @โsentry-internal/tracing (added, 7.120.3)
๐ @โsentry/core (added, 7.120.3)
๐ @โsentry/integrations (added, 7.120.3)
๐ @โsentry/node (added, 7.120.3)
๐ @โsentry/types (added, 7.120.3)
๐ @โsentry/utils (added, 7.120.3)
๐ boolean (added, 3.2.0)
๐ define-data-property (added, 1.1.4)
๐ detect-node (added, 2.1.0)
๐ es-define-property (added, 1.0.1)
๐ es-errors (added, 1.3.0)
๐ es6-error (added, 4.1.1)
๐ global-agent (added, 3.0.0)
๐ globalthis (added, 1.0.4)
๐ gopd (added, 1.2.0)
๐ has-property-descriptors (added, 1.0.2)
๐ immediate (added, 3.0.6)
๐ lie (added, 3.1.1)
๐ localforage (added, 1.10.0)
๐ matcher (added, 3.0.0)
๐ roarr (added, 2.15.4)
๐ semver (added, 7.7.2)
๐ semver-compare (added, 1.0.0)
๐ serialize-error (added, 7.0.1)
๐ sprintf-js (added, 1.1.3)
๐ type-fest (added, 0.13.1)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase
.All Depfu comment commands