Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency snyk to v1.996.0 [SECURITY] #434

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 20, 2022

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
snyk 1.575.0 -> 1.996.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-40764

Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.


Release Notes

snyk/snyk (snyk)

v1.996.0

Compare Source

Bug Fixes
  • bump golang plugin version (8893f81)
Features

v1.995.0

Compare Source

Bug Fixes
  • matching configurations error on gradle version catalog (20dcdae)

v1.994.0

Compare Source

Bug Fixes
Features
  • add custom severities to iac test config (9d86574)
  • add ignore count in the experimental version of iac test (d390ca2)
  • Added support for depth-detection (8cf1815)

v1.993.0

Compare Source

Features

v1.992.0

Compare Source

Bug Fixes
  • --target-name bug (3431f79)
  • Spacing for issue descriptions with custom rules (29b2fdb)

v1.991.0

Compare Source

Features
  • add report summary (d8e4ea8)
  • pass policy (.snyk) to iac-test via the config file. (6d3ad76)

v1.990.0

Compare Source

Bug Fixes
  • none custom policies severity issues should be filtered out before sending them to registry (4acacd2)

v1.989.0

Compare Source

Bug Fixes
  • downgrade snyk-go-plugin to 1.19.0 (4643026)
  • increase buffer size (8079fe3)
  • update golang plugin (a0e30d9)
  • upgrade-docker-registry-v2-client (275afb1)
Features
  • pass remote-repo-url arg to snyk-iac-test (18e8c87)

v1.988.0

Compare Source

Bug Fixes
  • return exit code 3 when no resources can be found (9d2e41f)
  • upgrade docker-registry-v2-client lib (374ba55)
Features
  • pass target-name arg to snyk-iac-test (4352122)
  • stop caching rules (71c866e)

v1.987.0

Compare Source

Bug Fixes
  • correct broken URLs for license issues (8a46931)
  • Ensured the test spinner stops (5d9d15f)
Features
  • remove reachability (5500e25)
  • scan maven aggregate projects (019bc45)
  • share cache path with IaC plugin (e254c0c)
  • update snyk-iac-test to 0.18.1 (379fe0c)

v1.986.0

Compare Source

Bug Fixes
  • wrong 2x count of iac issues with --report -multi-doc yaml (06da34e)

v1.985.0

Compare Source

Bug Fixes
  • Fixed incomplete CC path when missing resource attributes (6a4480c)
  • missing release in package version string (dcb40ab)
  • upgarde docker-registry-v2-client lib (5de3cb1)
Features
  • introduce —about flag to print attribution information (60eaec8)
  • pass projectTags arg to snyk-iac-test (ae70c1e)

v1.984.0

Compare Source

v1.983.0

Compare Source

Bug Fixes
Features
  • add project attributes support in --experimental (08791f8)
  • Implement AnyAuth Proxy Authentication support (467b621)

v1.982.0

Compare Source

Bug Fixes
  • upgrade docker plugin to improve stream parsing (a59d8e4)
Features
  • pass configuration to snyk-iac-test (6fb5992)
  • upgrade snyk iac test to 0.13.1 (ce7103e)

v1.981.0

Compare Source

Bug Fixes
  • Add missing IaC issue props in JSON output (da3a671)

v1.980.0

Compare Source

Features
  • improve maven debug logging (a0cdcfc)

v1.979.0

Compare Source

Bug Fixes
  • handle gradle strict lock mode (8905252)

v1.978.0

Compare Source

Features
  • add SARIF support (CFG-1993) (622c8f4)

v1.977.0

Compare Source

Bug Fixes
  • container app vulns json with experimental flag (332d87b)
Features
  • add deprecation message to test command (7f191b5)

v1.976.0

Compare Source

Features
  • improve comment handling for SBT scans (cf862b9)

v1.975.0

Compare Source

Features
  • add test summary section to the experimental output (b708086)

v1.974.0

Compare Source

Features
  • add 'target-name' flag support (6305c3d)

v1.973.0

Compare Source

Bug Fixes
  • vuln links using demunge (01154c9)
Features
  • add --remote-repo-url to "iac test" (2a12048)
  • update general vuln descriptions to point to pvdb (ad80d74)
  • update spotlight vuln descriptions (f536c9d)

v1.972.0

Compare Source

Bug Fixes
  • handle errors from /share-results (5871079)
Features
  • Add support for severity threshold (6833389)

v1.971.0

Compare Source

Features
  • snyk-iac-test error handling (3b3fa89)

v1.970.0

Compare Source

v1.969.0

Compare Source

Features
  • officially support Gradle 7 scanning (314dc96)

v1.968.0

Compare Source

Features
  • remove support for paths outside the current working directory (5ca35c1)

v1.967.0

Compare Source

Bug Fixes

v1.966.0

Compare Source

Bug Fixes
  • bump cloud-config-parser (38502ed)

v1.965.0

Compare Source

Bug Fixes
  • return paths for files that errrored (IaC) (d53afde)

v1.964.0

Compare Source

Features
  • add JSON support (4c636da)
  • bump snyk-iac-test version (0599c71)
  • improve Snyk API URL configuration (5a0bcbe)

v1.963.0

Compare Source

Bug Fixes

v1.962.0

Compare Source

Bug Fixes
  • typo in IaC v2 --report output (a22ab2e)
Features
  • container json response with app vulns (8aba337)

v1.961.0

Compare Source

Bug Fixes
  • move checkPaths() function out of main() (503d64c)

v1.960.0

Compare Source

Bug Fixes
  • fix parser error in tfplan parser (1976175)

v1.959.0

Compare Source

Bug Fixes
Features

v1.958.0

Compare Source

Bug Fixes
  • bump driftctl (dae3c8e)
  • reduce default snyk-gradle-plugin logging (6e26bdc)

v1.957.0

Compare Source

Bug Fixes
  • wrong dependencyCount in support of snyk-to-html (1065dd9)

v1.956.0

Compare Source

Bug Fixes
  • support HTTP(S) proxies in iac-test (3ac3ad0)

v1.955.0

Compare Source

Bug Fixes
  • also add HTTP_PROXY environment variable (78d0602)
Features
  • add support for requirements.txt files with BOM encoding (d31974f)
  • support for unmanaged snyk-to-html (83b4f6a)

v1.954.0

Compare Source

Features
  • add additinal arguments ability for go projects (7c915d4)

v1.953.0

Compare Source

Features
  • remove gradle-accept-legacy-config-roles flag (b4164e8)

v1.952.0

Compare Source

Bug Fixes

v1.951.0

Compare Source

Features
  • remove report command from snyk iac (9cd5813)

v1.950.0

Compare Source

Features
  • prune across Gradle dep-graph (44f75ff)

v1.949.0

Compare Source

Bug Fixes
  • include the custom rules warning if feature flag is not enabled (44e892b)

v1.948.0

Compare Source

Features

v1.947.0

Compare Source

Bug Fixes
  • IaC issue info when impact or description are missing (e785a64)
  • remove warning message from iac --report (b1aee5d)
Features
  • improve error message for iac describe (c58b5af)

v1.946.0

Compare Source

v1.945.0

Compare Source

Features
  • enable TF Vars Support for all (eedd239)

v1.944.0

Compare Source

v1.943.0

Compare Source

Features
  • detect JARs in WARs files inside containers (2924955)

v1.942.0

Compare Source

v1.941.0

Compare Source

v1.940.0

Compare Source

Bug Fixes
  • maven scan all unmanaged (2c543e3)

v1.939.0

Compare Source

Features
  • wrap new IaC output with a new FF (12e66bf)

v1.938.0

Compare Source

Bug Fixes
  • maven nested module scans (9cba63a)
Features

v1.937.0

Compare Source

Bug Fixes
  • remove driftctl brand in drift html output (3958fd1)

v1.936.0

Compare Source

Bug Fixes
  • (iac) last error does not override previous (d9e3449)
Features
  • unmanaged support for remote-repo-url (646c976)

v1.935.0

Compare Source

Bug Fixes
  • unmanaged cancelled jobs (dca7769)

v1.934.0

Compare Source

Features
  • include thrown errors in IaC failures section (571d3b8)

v1.933.0

Compare Source

Features

v1.932.0

Compare Source

Bug Fixes
  • allow endpoint to be modified when invalid (a4bc484)
  • CLI output styling (0e31b8e)

v1.931.0

Compare Source

Bug Fixes
  • ignore errors on multiple paths if there were some results (42e28c5)
  • use correct auth header for api requests (36211dd)

v1.930.0

Compare Source

Bug Fixes
  • gradle projects producing multiple jsondeps (c449cfc)

v1.929.0

Compare Source

Features

Changes to Gradle plugin:

  • upgrade default Node version 8 to 16 and include tests for Node, JDK and Gradle versions
  • lint README and config file
  • update PR review template

v1.928.0

Compare Source

v1.927.0

Compare Source

Features
  • Add progress indicator (764e0ce)
  • Rename Invalid Files section for IaC (1d21526)

v1.926.0

Compare Source

v1.925.0

Compare Source

Bug Fixes
  • git targets for variadic paths (f210f1a)
  • Include check for quiet option when logging (afea1b4)
Features
  • upgrade code client to 4.12.2 (aac7016)

v1.924.0

Compare Source

Features

v1.923.0

Compare Source

Features
  • support base64 encoding (b945b0c)

v1.922.0

Compare Source

Bug Fixes
  • Don't create duplicated IaC projects when sharing results (041ed24)
  • Ensure that IaC shared results paths use forward slashes (6f548ef)
  • SARIF output IaC (d07b434)

v1.921.0

Compare Source

Bug Fixes
  • link to correct snyk fix docs (5b96c29)

v1.920.0

Compare Source

Features
  • bump snyk-mvn-plugin version (8e45fc6)

v1.919.0

Compare Source

Bug Fixes
  • add tracking of contributors in unmanaged monitoring (0a2f8ce)

v1.918.0

Compare Source

Bug Fixes
  • iac describe: enable --deep when using --all (7651dc2)
Features
  • Implemented new issue description (c339455)

v1.917.0

Compare Source

Bug Fixes
  • add diagnostics to .Net manifest parser (8c2f174)
Features
  • deprecation notice when user run snyk iac report (c249296)

v1.916.0

Compare Source

v1.915.0

Compare Source

Features
  • remove-deeproxy-url-configuration (9202cd2)

v1.914.0

Compare Source

Bug Fixes
  • add debug logs to snyk-mvn-plugin (df31b57)

v1.913.0

Compare Source

Bug Fixes
  • bump maven plugin version (ce01fbe)
  • set rule index result by security rules mapping (37d4704)

v1.912.0

Compare Source

CLI Help updates

v1.911.0

Compare Source

v1.910.0

Compare Source

Bug Fixes
  • Skip unsupported IaC files (22f20e0)
Features
  • add --json-file-output support to code test (b97d0e6)

v1.909.0

Compare Source

Features
  • Added message for no issues found (96dbc7c)
  • bump-snyk-mvn-plugin (5eb7e57)
  • more logs in code in -d mode (1890c73)

v1.908.0

Compare Source

Bug Fixes
  • Exclude error results from IaC test summary (9adb3ee)
  • Remove none severity from test summary (39fa419)
  • unmanaged target reference (f1f1ebe)
Features
  • developer flag to override IaC bundle path (4403368)

v1.907.0

Compare Source

Features
  • change output for describe command (2fc2174)
  • Implemented failures section (5f7540d)

v1.906.0

Compare Source

Bug Fixes
  • Unbold severity section titles in IaC test output (65ef83f)

v1.905.0

Compare Source

Features
  • restructure the issues list layout (42a4d83)

v1.904.0

Compare Source

Bug Fixes
  • Fixed unpassing acceptance tests for IaC output (91a29cd)
  • Support scanning files with BOMs (3f00da9)
Features
  • Applied the new test summary formatter to the test flow (d348b04)

v1.903.0

Compare Source

v1.902.0

Compare Source

Features
  • Load TF variable definitions files via --var-file (141b6c0)

v1.901.0

Compare Source

Features
  • bump driftctl version to v0.27.0 (0e2f37f)

v1.900.0

Compare Source

Bug Fixes
  • support --project-name for unmanaged projects (0778479)

v1.899.0

Compare Source

Bug Fixes
  • Fix invalid JSON path in IaC test summary test (3935b68)
Features
  • Added implementation for IaC test summary formatter (19502c0)

v1.898.0

Compare Source

Features
  • Add an initial user message to the test output (f3475a9)

v1.897.0

Compare Source

Bug Fixes
  • scan-failing-on-empty-folder (53f35af)
Features
  • produce flat dep-graph scanning unmanaged (d52a147)

v1.896.0

Compare Source

  • Changed error message

v1.895.0

Compare Source

Features
  • log files over size limit (78376fb)

v1.894.0

Compare Source

Features
  • support metadata for excluded paths (034c638)
  • unmanaged cpp support for expiry policy (c01211e)

v1.893.0

Compare Source

v1.892.0

Compare Source

Features
  • drop Node.js 10 support (1e290f6)
  • remove --json-file-output for snykl iac describe (bc04b5e)
  • remove protect (d25bb57)
  • remove wizard (0797fca)
BREAKING CHANGES
  • Running Snyk CLI with Node v10 is no longer supported

v1.891.0

Compare Source

v1.890.0

Compare Source

Bug Fixes
  • Enforce test limits when creating IaC projects (5d7fd4b)
Features
  • use sbt plugin with improvements (194b5f8)

v1.889.0

Compare Source

v1.888.0

Compare Source

Bug Fixes
  • code-client update to v4.9.0 (2ce5a4b)

v1.887.0

Compare Source

Bug Fixes
  • Increase delay between inputs on some acceptance tests (41b7f9e)
Features
  • drift: use snyk brand on html output (c0f7458)

v1.886.0

Compare Source

v1.885.0

Compare Source

Bug Fixes
  • iac report acceptence test (a74c2e2)
  • point to the correct projects collection in the platform (0a98806)

v1.884.0

Compare Source

Bug Fixes
  • honor --org flag in snyk iac test --report (f371b26)
  • skip broken patch test (5f96e4c)
Features
  • Add support for --target-reference to CLI Share Results (f7ebcac)
  • Created report command for IaC (3570f7a)

v1.883.0

Compare Source

Features
  • display policy's exclude entries (dee758c)

v1.882.0

Compare Source

Bug Fixes
  • docs: improve rendering of code examples (ea48650)
Features
  • Add support for IaC project tags and attributes (03b24df)

v1.881.0

Compare Source

Features
  • Add contributing devs to share results (8ac653a)
  • Add git info to share results (3be2c7d)

v1.880.0

Compare Source

Features
  • ignore issue support for c/c++ flows (f1623e4)

v1.879.0

Compare Source

Bug Fixes
  • don't send drift excludes to analytics (4a722f1)

v1.878.0

Compare Source

Bug Fixes
  • multi-file Kubernetes resource scanning (b975e69)

v1.877.0

Compare Source

Features
  • add support for locals referencing locals (7b77015)

v1.876.0

Compare Source

Bug Fixes
  • redact driftctl headers to fetch tfstate (7c486de)
  • redact sensitive flag values from analytics (33c8c49)

v1.875.0

Compare Source

Features
  • Allow to lookup for driftctl in /bin (6ade2a0)
  • validate describe arg and show help (9c4eef3)

v1.874.0

Compare Source

Bug Fixes
  • unmanaged cpp error message (a352e78)

v1.873.0

Compare Source

Bug Fixes
  • should add is-iac-drift on error exit code too (4a48c98)
Features
  • iac-describe driftignore support in policy (582f1a9)

v1.872.0

Compare Source

v1.871.0

Compare Source

Features
  • add drift analytics to be sent to registry (01876f1)

v1.870.0

Compare Source

Features
  • unmanaged cpp snyk policy support (7168711)

v1.869.0

Compare Source

Features
  • add support for snyk policy (b36ae33)

v1.868.0

Compare Source

Bug Fixes
  • non-tf single files scan successfully in new flow (f827f79)

v1.867.0

Compare Source

Bug Fixes
  • upgrade snyk-python-plugin (3e440c9)
Features

v1.866.0

Compare Source

v1.865.0

Compare Source

Features
  • update snyk-iac-parsers version (2254853)

v1.864.0

Compare Source

Features

v1.863.0

Compare Source

Bug Fixes
  • add --no-version-check flag to driftctl (56be94b)
  • maven root project scan exclude aggregate projects (d9bc1ab)

v1.862.0

Compare Source

Features
  • Add TF Variable support for nested directories (336828d)

v1.861.0

Compare Source

Features
  • log protect removal message (f6078d8)
  • wizard removal message (382024b)

v1.860.0

Compare Source

Bug Fixes
  • correctly resolve policy file in path containing ".snyk" (1adb784)
Features
  • adapt iac drift exits codes to snyk cli (f978bb7)
  • add service flag to iac drift command (d9c082a)
  • allow multiple from params to snyk iac drift (6d759d2)

v1.859.0

Compare Source

Features
  • resolve single depth of references (e8d445c)

v1.858.0

Compare Source

Features

v1.857.0

Compare Source

Bug Fixes
  • use path separator for all OSes in tfvars (8651b22)
Features
  • add iac drift gen-driftignore command (36ddda8)
  • add debug logs for tf vars (356abe8)
  • add help page for iac-drift-scan (546f1b0)
  • add org name to snyk code test (33097ce)
  • dereference variables from terraform.tfvars and *.auto.tfvars (c2f7e94)
  • remove vulndb ff for unmanaged (c251a7d)

v1.856.0

Compare Source

Bug Fixes
  • support dependencies with unknown version (0b8100c)

v1.855.0

Compare Source

Bug Fixes
  • bumped up code-client feater (b0de91a)
Features
  • tf variable dereferencing (133cf03)

v1.854.0

Compare Source

Features
  • observability in snyk code (5d8fd20)

v1.853.0

Compare Source

Bug Fixes
  • don't override debug namespace (1e80b8c)
Performance Improvements
  • Fix OOM issues caused by group-issues (09215cf)

v1.852.0

Compare Source

Bug Fixes
  • max-depth argument for unmanaged flows (c55f5c0)

[v1.851.0](https://redirect


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Contributor Author

renovate bot commented Nov 20, 2022

⚠ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package-lock.json

File name: package.json
Post-upgrade command 'npm run lintfix' has not been added to the allowed list in allowedPostUpgradeCommands
File name: package.json
Post-upgrade command 'npm run build:client' has not been added to the allowed list in allowedPostUpgradeCommands

@renovate renovate bot force-pushed the renovate/npm-snyk-vulnerability branch from e03cd62 to c85f83e Compare May 28, 2023 09:47
@renovate renovate bot changed the title Update dependency snyk to v1.996.0 [SECURITY] Update dependency snyk to v1.1064.0 [SECURITY] May 28, 2023
@renovate renovate bot force-pushed the renovate/npm-snyk-vulnerability branch from c85f83e to 9bf6af5 Compare August 6, 2024 06:54
@renovate renovate bot changed the title Update dependency snyk to v1.1064.0 [SECURITY] Update dependency snyk to v1.996.0 [SECURITY] Aug 6, 2024
Copy link
Contributor Author

renovate bot commented Aug 6, 2024

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: package.json
Post-upgrade command 'npm run lintfix' has not been added to the allowed list in allowedPostUpgradeCommands
File name: package.json
Post-upgrade command 'npm run build:client' has not been added to the allowed list in allowedPostUpgradeCommands

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants