Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade snyk from 1.621.0 to 1.819.0 #2335

Closed

Conversation

snyk-bot
Copy link
Contributor

Snyk has created this PR to upgrade snyk from 1.621.0 to 1.819.0.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 198 versions ahead of your current version.
  • The recommended version was released 21 days ago, on 2022-01-07.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-SSH2-1656673
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Regular Expression Denial of Service (ReDoS)
SNYK-JS-PARSELINKHEADER-1582783
589/1000
Why? Has a fix available, CVSS 7.5
No Known Exploit
Prototype Pollution
SNYK-JS-LODASHSET-1320032
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-JSZIP-1251497
589/1000
Why? Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: snyk
  • 1.819.0 - 2022-01-07

    1.819.0 (2022-01-07)

    Features

    • pick up SBT plugin with improved logic (675125d)
  • 1.818.0 - 2022-01-06

    1.818.0 (2022-01-06)

    Bug Fixes

    • Remove scanResult from json output (fcff339)
  • 1.817.0 - 2022-01-05

    1.817.0 (2022-01-05)

    Bug Fixes

    • critical level is considered error in sarif (a034e57)
  • 1.816.0 - 2022-01-04

    1.816.0 (2022-01-04)

    Features

    • --all-projects skips failed workspaces (2e5effe)
    • support yarn workspaces projects in --all-projects (a6374b1)
  • 1.815.0 - 2022-01-04

    1.815.0 (2022-01-04)

    Features

    • yaml support for iac wasm bundles (4cbc544)
  • 1.814.0 - 2022-01-03

    1.814.0 (2022-01-03)

    Features

    • add link to docs for base image remediation (920c83b)
  • 1.813.0 - 2021-12-31

    1.813.0 (2021-12-31)

    Bug Fixes

    • custom rules output for sarif (e18adef)
  • 1.812.0 - 2021-12-29

    1.812.0 (2021-12-29)

    Features

    • include os architecture in analytics (3202e8e)
  • 1.811.0 - 2021-12-28

    1.811.0 (2021-12-28)

    Bug Fixes

    • Allow grouping of vulns for multiple oss results json (756f226)
  • 1.810.0 - 2021-12-28

    1.810.0 (2021-12-28)

    Bug Fixes

    • show msg only if no dockerfile and not autodetect base image (27ab97b)
  • 1.809.0 - 2021-12-23
  • 1.808.0 - 2021-12-23
  • 1.807.0 - 2021-12-23
  • 1.806.0 - 2021-12-21
  • 1.805.0 - 2021-12-21
  • 1.804.0 - 2021-12-21
  • 1.803.0 - 2021-12-20
  • 1.802.0 - 2021-12-20
  • 1.801.0 - 2021-12-20
  • 1.800.0 - 2021-12-20
  • 1.799.0 - 2021-12-20
  • 1.798.0 - 2021-12-20
  • 1.797.0 - 2021-12-17
  • 1.796.0 - 2021-12-17
  • 1.795.0 - 2021-12-17
  • 1.794.0 - 2021-12-16
  • 1.793.0 - 2021-12-15
  • 1.792.0 - 2021-12-14
  • 1.791.0 - 2021-12-14
  • 1.790.0 - 2021-12-12
  • 1.789.0 - 2021-12-10
  • 1.788.0 - 2021-12-10
  • 1.787.0 - 2021-12-08
  • 1.786.0 - 2021-12-07
  • 1.785.0 - 2021-12-06
  • 1.784.0 - 2021-12-06
  • 1.783.0 - 2021-12-03
  • 1.782.0 - 2021-12-02
  • 1.781.0 - 2021-12-02
  • 1.780.0 - 2021-11-30
  • 1.779.0 - 2021-11-30
  • 1.778.0 - 2021-11-29
  • 1.777.0 - 2021-11-29
  • 1.776.0 - 2021-11-29
  • 1.775.0 - 2021-11-26
  • 1.774.0 - 2021-11-26
  • 1.773.0 - 2021-11-24
  • 1.772.0 - 2021-11-24
  • 1.771.0 - 2021-11-24
  • 1.770.0 - 2021-11-24
  • 1.769.0 - 2021-11-23
  • 1.768.0 - 2021-11-23
  • 1.767.0 - 2021-11-21
  • 1.766.0 - 2021-11-19
  • 1.765.0 - 2021-11-19
  • 1.764.0 - 2021-11-18
  • 1.763.0 - 2021-11-15
  • 1.762.0 - 2021-11-15
  • 1.761.0 - 2021-11-15
  • 1.760.0 - 2021-11-11
  • 1.759.0 - 2021-11-09
  • 1.758.0 - 2021-11-09
  • 1.757.0 - 2021-11-08
  • 1.756.0 - 2021-11-08
  • 1.755.0 - 2021-11-08
  • 1.754.0 - 2021-11-08
  • 1.753.0 - 2021-11-05
  • 1.752.0 - 2021-11-03
  • 1.751.0 - 2021-11-03
  • 1.750.0 - 2021-11-02
  • 1.749.0 - 2021-10-31
  • 1.748.0 - 2021-10-29
  • 1.747.0 - 2021-10-28
  • 1.746.0 - 2021-10-27
  • 1.745.0 - 2021-10-25
  • 1.744.0 - 2021-10-21
  • 1.743.0 - 2021-10-21
  • 1.742.0 - 2021-10-20
  • 1.741.0 - 2021-10-19
  • 1.740.0 - 2021-10-19
  • 1.739.0 - 2021-10-19
  • 1.738.0 - 2021-10-18
  • 1.737.0 - 2021-10-14
  • 1.736.0 - 2021-10-13
  • 1.735.0 - 2021-10-12
  • 1.734.0 - 2021-10-12
  • 1.733.0 - 2021-10-07
  • 1.732.0 - 2021-10-07
  • 1.731.0 - 2021-10-05
  • 1.730.0 - 2021-10-03
  • 1.729.0 - 2021-10-01
  • 1.728.0 - 2021-09-29
  • 1.727.0 - 2021-09-28
  • 1.726.0 - 2021-09-28
  • 1.725.0 - 2021-09-28
  • 1.724.0 - 2021-09-28
  • 1.723.0 - 2021-09-27
  • 1.722.0 - 2021-09-26
  • 1.721.0 - 2021-09-26
  • 1.720.0 - 2021-09-22
  • 1.719.0 - 2021-09-22
  • 1.718.0 - 2021-09-22
  • 1.717.0 - 2021-09-17
  • 1.716.0 - 2021-09-16
  • 1.715.0 - 2021-09-15
  • 1.714.0 - 2021-09-15
  • 1.713.0 - 2021-09-14
  • 1.712.0 - 2021-09-14
  • 1.711.0 - 2021-09-14
  • 1.710.0 - 2021-09-14
  • 1.709.0 - 2021-09-13
  • 1.708.0 - 2021-09-13
  • 1.707.0 - 2021-09-12
  • 1.706.0 - 2021-09-12
  • 1.705.0 - 2021-09-12
  • 1.704.0 - 2021-09-09
  • 1.703.0 - 2021-09-09
  • 1.702.0 - 2021-09-09
  • 1.701.0 - 2021-09-08
  • 1.700.0 - 2021-09-08
  • 1.699.0 - 2021-09-08
  • 1.698.0 - 2021-09-07
  • 1.697.0 - 2021-09-05
  • 1.696.0 - 2021-09-01
  • 1.695.0 - 2021-08-29
  • 1.694.0 - 2021-08-27
  • 1.693.0 - 2021-08-27
  • 1.692.0 - 2021-08-26
  • 1.691.0 - 2021-08-26
  • 1.690.0 - 2021-08-26
  • 1.689.0 - 2021-08-25
  • 1.688.0 - 2021-08-25
  • 1.687.0 - 2021-08-23
  • 1.686.0 - 2021-08-23
  • 1.685.0 - 2021-08-23
  • 1.684.0 - 2021-08-20
  • 1.683.0 - 2021-08-16
  • 1.682.0 - 2021-08-16
  • 1.681.0 - 2021-08-13
  • 1.680.0 - 2021-08-12
  • 1.679.0 - 2021-08-11
  • 1.678.0 - 2021-08-11
  • 1.677.0 - 2021-08-09
  • 1.676.0 - 2021-08-05
  • 1.675.0 - 2021-08-03
  • 1.674.0 - 2021-08-02
  • 1.673.0 - 2021-08-02
  • 1.672.0 - 2021-07-30
  • 1.671.0 - 2021-07-29
  • 1.670.0 - 2021-07-29
  • 1.669.0 - 2021-07-28
  • 1.668.0 - 2021-07-27
  • 1.667.0 - 2021-07-26
  • 1.666.0 - 2021-07-22
  • 1.665.0 - 2021-07-22
  • 1.664.0 - 2021-07-20
  • 1.663.0 - 2021-07-18
  • 1.662.0 - 2021-07-15
  • 1.661.0 - 2021-07-14
  • 1.660.0 - 2021-07-13
  • 1.659.0 - 2021-07-13
  • 1.658.0 - 2021-07-09
  • 1.657.0 - 2021-07-07
  • 1.656.0 - 2021-07-07
  • 1.655.0 - 2021-07-06
  • 1.654.0 - 2021-07-06
  • 1.653.0 - 2021-07-02
  • 1.652.0 - 2021-06-30
  • 1.651.0 - 2021-06-30
  • 1.650.0 - 2021-06-28
  • 1.649.0 - 2021-06-28
  • 1.648.0 - 2021-06-28
  • 1.647.0 - 2021-06-28
  • 1.646.0 - 2021-06-25
  • 1.645.0 - 2021-06-24
  • 1.644.0 - 2021-06-24
  • 1.643.0 - 2021-06-23
  • 1.642.0 - 2021-06-23
  • 1.641.0 - 2021-06-22
  • 1.640.0 - 2021-06-22
  • 1.639.0 - 2021-06-17
  • 1.638.0 - 2021-06-17
  • 1.637.0 - 2021-06-17
  • 1.636.0 - 2021-06-17
  • 1.635.0 - 2021-06-17
  • 1.634.0 - 2021-06-16
  • 1.633.0 - 2021-06-16
  • 1.632.0 - 2021-06-16
  • 1.631.0 - 2021-06-15
  • 1.630.0 - 2021-06-11
  • 1.629.0 - 2021-06-11
  • 1.628.0 - 2021-06-10
  • 1.627.0 - 2021-06-10
  • 1.626.0 - 2021-06-10
  • 1.625.0 - 2021-06-10
  • 1.624.0 - 2021-06-09
  • 1.623.0 - 2021-06-08
  • 1.622.0 - 2021-06-04
  • 1.621.0 - 2021-06-02
from snyk GitHub release notes
Commit messages
Package name: snyk

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@inlguy inlguy closed this Dec 7, 2022
@mcdonnnj mcdonnnj deleted the snyk-upgrade-98efcd433db0f3cc42f09c411f2333fa branch June 5, 2024 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants