Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 30, 2025

This PR contains the following updates:

Package Type Update Change OpenSSF
snyk dependencies minor 1.1294.2 -> 1.1297.3 OpenSSF Scorecard

Snyk CLI Insertion of Sensitive Information into Log File allowed in DEBUG or DEBUG/TRACE mode

CVE-2025-6624 / GHSA-6hwc-9h8r-3vmf / GO-2025-3789

More information

Details

Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via environment variables or command line arguments can be exposed when executing Snyk CLI in DEBUG or DEBUG/TRACE mode.

The issue affects the following Snyk commands:

  1. When snyk container test or snyk container monitor commands are run against a container registry, with debug mode enabled, the container registry credentials may be written into the local Snyk CLI debug log. This only happens with credentials specified in environment variables (SNYK_REGISTRY_USERNAME and SNYK_REGISTRY_PASSWORD), or in the CLI (--password/-p and --username/-u).

  2. When snyk auth command is executed with debug mode enabled AND the log level is set to TRACE, the Snyk access / refresh credential tokens used to connect the CLI to Snyk may be written into the local CLI debug logs.

  3. When snyk iac test is executed with a Remote IAC Custom rules bundle, debug mode enabled, AND the log level is set to TRACE, the docker registry token may be written into the local CLI debug logs.

Severity

  • CVSS Score: 7.2 / 10 (High)
  • Vector String: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

snyk/snyk (snyk)

v1.1297.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • logging: Improves the sanitization of credentials in local debug logs. (38322f3)

v1.1297.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • logging: Improves the sanitization of credentials in local debug logs. (e054455)
  • language-server: IDE Connectivity for Proxy Users: Fixes an issue where IDE plugins could fail to connect when operating behind an NTLM proxy.
  • language-server: Snyk Code Local Engine Fix: Addresses a regression that prevented the Snyk Code Local Engine (SCLE) from functioning correctly within the IDEs.

v1.1297.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • test: Rollbacked a regression introduced by a change in gradle module resolution in version 1.1297.0 (7991133)

v1.1297.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features
  • container: Support scanning container images from tar files without specifying a type (58b0861)
  • iac: Improve IaC deployment to avoid on the fly downloads (5108f58)
  • sbom: Introduce sbom monitor command (24e96c3)
  • test: Improve gradle module resolution (7991133)
  • language-server: Introduce explanation of AI fixes in IDEs (74fa322)
Bug Fixes
  • container: Fix issue when scanning invalid node manifest files (ceb8020)
  • code: Fix hash mismatches for files containing non-UTF-8 content (33d33e9)
  • iac: Ensure to use the correct org id when sharing results for v2 (1c4094a)
  • iac: Ensure to use target-name (2201f0a)
  • sbom: Fix issues when generating sboms based on NuGet .sln (80c43d9)
  • test: Fix issues when scanning gradle projects on Windows (11586cc)
  • test: Improve error messages when using fail-fast, all-projects and json (a396bd6)
  • test: Fix yarn 2 out of sync issues (18aee45)
  • test: Fix pnpm out of sync issue for duplicated peer and dev dependencies (2581e16)
  • test: Ensure internal dependencies are represented correctly when normalizing Gradle dependencies (c7e2713)
  • test: Fix testing composer-based PHP projects (39e3379)
  • language-server: Fix and improve issue filtering in IDEs (a474d67)
  • language-server: Fix unmanaged C/C++ scans with '—unmanaged' flag in additional parameters (01f53e3)
  • language-server: Fix applying Snyk Code AI fixes on the wrong lines (01f53e3)

v1.1296.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • mcp: Add experimental Model Context Protocol server for agentic workflow support (3b5f494)
Bug Fixes
  • general: Fix OAuth authentication issues (b2684db)
  • code: Write JSON/SARIF files when nested directories do not exist (faca897)
  • test: Clearer error messages when testing multiple projects with fail-fast (a396bd6)

v1.1296.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • test: Add poetry v2 support (49c6652)
  • code: Fix backward compatibility issue in sarif driver name (5ef6442)
  • iac: Fix iac test network issues (815ed82)
  • language-server: Increase authentication resilience (07fc381)
  • language-server: Avoid that the trust dialog blocks the application. (07fc381)
  • language-server: Fix duplicate Open Source Issues appearing only in a single IDE tree node, despite occurring in multiple files. (07fc381)
  • dependency: Upgrade golang.org/x/net to address CVE-2025-22870 (7edd450)

v1.1296.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

News
  • general: Improved error logging and handling
Features
  • container: add support for --exclude-node-modules option (4756f27)
  • container: adds kaniko support (bfb69c8)
  • general: display a unique interactionID alongside each error (960a71c)
  • test: python support for local wheel files specifiers (42675eb)
  • test: dep-graph json file output (90f24ec)
  • test: print legacy tree with json file output (b256937)
  • test: display all applicable maven unmanaged identities (ebf6ba1)
  • code: enable v1 fingerprints in code sarif output (00644af)
  • test: Add 'pkgIdProvenance' labels to dependency graph nodes when the package identity has been changed from what has been discovered in the manifest files (4d529b3)
  • test: added Python support for sys_platform (1aa1565)
  • language-server AI fix explain (26d118f)
  • language-server enable calling mcp commands via ls commands (6f80a03)
  • language-server add scan source to metrics (6f80a03)
  • language-server add mcp server, refactoring (6f80a03)
  • language-server added a new code action and code lens for showDocument (8e7ab06)
  • language-server add Option for Pre-Scan command, fix auth race (64920ac)
  • language-server add ideStyle variable to static html (0a05e66)
  • language-server intiial commit of shared html for scan summary panel (0a05e66)
  • language-server send scan summary and scan base & working directory concurrently (1908a08)
  • language-server store folder config outside of git repo, add reference folder (50d0770)
  • language-server send initial summary panel notification (50d0770)
  • language-server add a new $/snyk.scanSummary notificiation (fc80c9c)
  • language-server support maven pom hierarchies for highlighting & fixes (e5924fc)
  • language-server Sending a user event when fixing inside the editor (e5924fc)
  • language-server Sending IDE+extension versions to autofix (a18975a)
Bug Fixes
  • container: add container test doc info for --exclude-node-modules (2faf2d1)
  • test: fix dotnet UTF-16LE support for target framework (e90075a)
  • test: reduce false positives when scanning improved dotnet projects (c21625a)
  • test: use --strict-out-of-sync when set to false with pnpm for top level dependencies (8d5b71a)
  • test: fix OutOfSync errors in pnpm for download urls (b6e4ea0)
  • test: fix OutOfSync errors in pnpm git protocol dependencies (5c8dc34)
  • code: Don't write sarif files when no results are found (5a15113)
  • code: Support single file test for golang native implementation (d7881f1)
  • sbom: mavenAggregateProject with Dverbose or sbom (e88cf71)
  • iac: Updates the user messages for snyk iac test --report for IaC V2 (1c9b3b3)
  • language-server check folder trust before opening/changing/saving file (26d118f)
  • language-server new issue summary totals (6f80a03)
  • language-server add correct lesson url for license issues (6f80a03)
  • language-server issues with non-UTF-8 encoded files in Snyk Code (8e7ab06)
  • language-server ignore first dataflow element for oss fingerprint (64920ac)
  • language-server use workdir folderConfig for ref Scan (64920ac)
  • language-server test bundle add size property (0a05e66)
  • language-server normalize path for file filter and reduce memory footprint (0a05e66)
  • language-server add ideScript to Summary html (0a05e66)
  • language-server add css variables and headers (0a05e66)
  • language-server panic in range_finder (50d0770)
  • language-server fix issue metadata used for hashing (fc80c9c)
  • language-server use diff without enricher for delta (b213b58)
  • language-server move issue view option filtering to the LS to not display ignored diagnostics in editor (b213b58)
  • language-server add api version query to explain API URL (b213b58)

v1.1295.4

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

v1.1295.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • security: Upgrades dependencies to address CVE-2025-21614
  • language-server: Improved memory usage when executing code scans on large projects
  • language-server: Fix incorrect filtering of files when executing code scans which could fail the analysis
  • language-server: Fix random unexpected logouts when using OAuth2 authentication

v1.1295.2

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • general: revert dependencies upgrade which introduced a regression on a number of Linux installations

v1.1295.1

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes
  • security: Upgrades goproxy to 1.5 to address a high severity vulnerability
  • security: Upgrades dependencies in IaC plugin to address CVE-2025-21614

v1.1295.0

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features
  • iac: include evidence field in json output [IAC-3161] (9487a08)
  • auth: auto detect API Url during OAuth authentication (6884511)
Bug Fixes
  • test: support verbose gradle graphs for sbom generation (600ef50)
  • general: prevent snyk-policy lib from interrupting stdout to ensure valid --json --sarif output (469edf5)
  • general: improved error messages around network requests (f6fc5f7)
  • general: only read SNYK_ prefixed env vars (5bfcbe8)
  • instrumentation: add default oss product for monitor as well (83cabc3)
  • container: optional dependencies are properly connected in the dep-graph (3205e66)
  • container: package-lock v3 missing sub-dependencies 94c9b7f)
  • container: support --exclude-app-vulns with oauth (73a75fa)
  • monitor: use error catalog messages for monitor commands (4e58601)
  • iac: extra error handling and debugging [IAC-3138] (7fbae0f)
  • iac: snyk-iac-test security update [IAC-3171] (fac22bb)
  • iac: update snyk-iac-parsers version [IAC-3138] (5326d9d)
  • iac: use proxy aware snyk-iac-test [INC-1647] (d5d1e2e)
  • test: do not treat warnings as errors on restore (d0113eb)
  • test:fix mismatch/off-by-one on unmanagedDependencyCount in the analytics logs UNIFY-340 (75d8e6d)
  • test: update snyk-nodejs-plugin to fix micromatch vuln (766bd1d)
  • test: upgrade mvn-plugin to handle jar scanning sha-not-found error (060380a)
  • test: fix runtime versions overwriting nuget versions (5e715cf)
  • instrumentation: stop sending CLI args in analytics (6d183fb)
  • policy update policy library to fix valid json output (0bc0aed)

v1.1294.3

Compare Source

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link

Deploying matt-travi-org with  Cloudflare Pages  Cloudflare Pages

Latest commit: aa94bcc
Status: ✅  Deploy successful!
Preview URL: https://96abe150.matt-travi-org.pages.dev
Branch Preview URL: https://renovate-npm-snyk-vulnerabil.matt-travi-org.pages.dev

View logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants