cisagov / cyber.dhs.gov

A site for CISA directives
https://cyber.dhs.gov
Other
157 stars 61 forks source link

[Snyk] Upgrade snyk from 1.676.0 to 1.696.0 #282

Closed snyk-bot closed 3 months ago

snyk-bot commented 2 years ago

Snyk has created this PR to upgrade snyk from 1.676.0 to 1.696.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Command Injection
SNYK-JS-SSH2-1656673
661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: snyk
  • 1.696.0 - 2021-09-01

    1.696.0 (2021-09-01)

    Bug Fixes

    • sbt plugin check global plugins (8e17939)

    Features

    • support yarn workspaces with transitives that are also workspaces (1797040)
  • 1.695.0 - 2021-08-29

    1.695.0 (2021-08-29)

    Features

    • Return vulns from shaded jars (8767af0)
  • 1.694.0 - 2021-08-27

    1.694.0 (2021-08-27)

    Features

    • fail fast when cliFailFast feature flag is set (747f8ce)
    • remove default HTML report from Docker images (cdc35ac)
  • 1.693.0 - 2021-08-27

    1.693.0 (2021-08-27)

    Features

    • add VS Code as an integration (28b66a6)
  • 1.692.0 - 2021-08-26

    1.692.0 (2021-08-26)

    Bug Fixes

    • @ snyk/fix: support deeply nested requires in req*.txt (c499b69)
  • 1.691.0 - 2021-08-26

    1.691.0 (2021-08-26)

    Bug Fixes

    • support oauth tokens for feature flags (0095f37)
  • 1.690.0 - 2021-08-26

    1.690.0 (2021-08-26)

    Bug Fixes

    • revert python plugin upgrade (1c7ff9f)
  • 1.689.0 - 2021-08-25

    1.689.0 (2021-08-25)

    Features

    • support critical severities in IaC (ff281c8)
  • 1.688.0 - 2021-08-25

    1.688.0 (2021-08-25)

    Features

    • use depGraph for pip projects (8e38796)
  • 1.687.0 - 2021-08-23

    1.687.0 (2021-08-23)

    Bug Fixes

    • don't render two newlines at the end (28ed154)
    • move alerts to stderr (5764b81)
  • 1.686.0 - 2021-08-23
  • 1.685.0 - 2021-08-23
  • 1.684.0 - 2021-08-20
  • 1.683.0 - 2021-08-16
  • 1.682.0 - 2021-08-16
  • 1.681.0 - 2021-08-13
  • 1.680.0 - 2021-08-12
  • 1.679.0 - 2021-08-11
  • 1.678.0 - 2021-08-11
  • 1.677.0 - 2021-08-09
  • 1.676.0 - 2021-08-05
from snyk GitHub release notes
Commit messages
Package name: snyk
  • 000a170 Merge pull request #2214 from snyk/chore/fix-npm-auth
  • 0f6fab9 Merge pull request #2213 from snyk/fix/sbt-plugin-check-global
  • 7854f0f chore(ci): fix npm authentication
  • 8e17939 fix: sbt plugin check global plugins
  • 0582efb Merge pull request #2205 from snyk/chore/enforce-es6-modules
  • 6d97050 Merge pull request #2212 from snyk/chore/fix-gh-cli
  • 170a22a chore: enforce usage of ES6 modules
  • 0354bb8 chore(ci): use correct github token env var
  • 5a8534c Merge pull request #2211 from snyk/feat/support-transitive-workspace-packages
  • a52ddeb Merge pull request #2202 from snyk/refactor/tidy-up-dep-graph-ff
  • 219c6d7 Merge pull request #2210 from snyk/chore/use-env-for-npm-token
  • 1797040 feat: support yarn workspaces with transitives that are also workspaces
  • ca4123f chore(ci): use env for npm token
  • b7c7c81 Merge pull request #2194 from snyk/chore/update-ci-node-versions
  • 7fc7ecf refactor: replace callbacks with async/await
  • 2913441 refactor: remove experimental-dep-graph flag
  • cc6debc Merge pull request #2207 from snyk/docs/readme
  • 7d61cc1 docs: update CLI readme
  • 392ccd7 Merge pull request #2200 from snyk/feat/shaded-jars-snanning
  • f23fc8b Merge pull request #2197 from snyk/test/use-fake-server-for-cli-args-tests
  • 44a75a6 test: disable analytics on jest acceptance tests
  • 208417d test: use fake server for cli-args acc tests
  • 0751804 Merge pull request #2173 from snyk/feat/cli-ff
  • 747f8ce feat: fail fast when `cliFailFast` feature flag is set
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

mcdonnnj commented 3 months ago

Snyk has been removed from the organization.