cisagov / cyber.dhs.gov

A site for CISA directives
https://cyber.dhs.gov
Other
157 stars 61 forks source link

Bump snyk from 1.676.0 to 1.813.0 #307

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps snyk from 1.676.0 to 1.813.0.

Release notes

Sourced from snyk's releases.

v1.813.0

1.813.0 (2021-12-31)

Bug Fixes

  • custom rules output for sarif (e18adef)

v1.812.0

1.812.0 (2021-12-29)

Features

  • include os architecture in analytics (3202e8e)

v1.811.0

1.811.0 (2021-12-28)

Bug Fixes

  • Allow grouping of vulns for multiple oss results json (756f226)

v1.810.0

1.810.0 (2021-12-28)

Bug Fixes

  • show msg only if no dockerfile and not autodetect base image (27ab97b)

v1.809.0

1.809.0 (2021-12-23)

Features

  • Adding support for private JARs (f456216)

v1.808.0

1.808.0 (2021-12-23)

Bug Fixes

  • remove false positive results from log4shell (42ef2b8)

v1.807.0

1.807.0 (2021-12-23)

... (truncated)

Commits
  • ed99593 Merge pull request #2493 from snyk/fix/custom-rules-sarif
  • 39464eb Merge pull request #2501 from snyk/docs/reorder-readme
  • baeed6d docs: reorder readme for better visibility of docs
  • e91a9bc Merge pull request #2446 from snyk/feat/analytics-arch
  • c2aa312 Merge pull request #2445 from snyk/chore/pipefail
  • 8f61b7f Merge pull request #2497 from snyk/chore/hidden-wizard
  • a75c451 Merge pull request #2469 from snyk/fix/enable-vuln-grouping-for-opensource-mu...
  • 1dec52f Merge pull request #2494 from snyk/chore/Base-image-remediation-advice
  • 27ab97b fix: show msg only if no dockerfile and not autodetect base image
  • 6bec415 Merge pull request #2500 from snyk/feat/support-private-jars
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Superseded by #310.