lowsky / spotify-graphql-server

A simple graphql server for spotify data, see blog
https://blog.codecentric.de/en/2017/01/lets-build-spotify-graphql-server/
57 stars 17 forks source link

fix(deps): update dependency @snyk/protect to v1.1292.1 #378

Closed renovate[bot] closed 2 months ago

renovate[bot] commented 6 months ago

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@snyk/protect 1.1281.0 -> 1.1292.1 age adoption passing confidence

Release Notes

snyk/snyk (@​snyk/protect) ### [`v1.1292.1`](https://togithub.com/snyk/cli/releases/tag/v1.1292.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1292.0...v1.1292.1) The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see [this documentation](https://docs.snyk.io/snyk-cli/releases-and-channels-for-the-snyk-cli) #### Complete changelog ##### Bug Fixes - **test,monitor**: fix improper permission error handling when accessing 'enablePnpmCli' feature flag ### [`v1.1292.0`](https://togithub.com/snyk/cli/releases/tag/v1.1292.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1291.1...v1.1292.0) The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see [this documentation](https://docs.snyk.io/snyk-cli/releases-and-channels-for-the-snyk-cli) ##### News This Snyk CLI release delivers an assortment of bug fixes and improvements. - We've added support for pnpm, giving you more flexibility in your project setup. - You can now scan npm/yarn projects even without lockfiles, ensuring comprehensive vulnerability detection regardless of your dependency management approach. - We're committed to strengthening security. This release includes redaction of additional sensitive data in debug logs, minimizing potential risks. #### Complete changelog ##### Features - **test:** Added pnpm support under 'enablePnpmCli' feature flag ([#​5181](https://togithub.com/snyk/snyk/issues/5181)) ([46769cc](https://togithub.com/snyk/snyk/commit/46769ccefc0c9ca98a44ad4bdd2b4d8161294dbf)) - **test:** Support scan of npm/yarn projects without lockfiles ([e2d77a9](https://togithub.com/snyk/snyk/commit/e2d77a93da3701f4ade32e7432f870945c3763b2)) - **monitor:** Set target-reference in the monitor request ([51ed8f5](https://togithub.com/snyk/snyk/commit/51ed8f53595d7545537900762836823ced29c958)) - **code:** Centrally check if code test is enabled ([#​5239](https://togithub.com/snyk/snyk/issues/5239)) ([e5a00e2](https://togithub.com/snyk/snyk/commit/e5a00e24cbe17b3b9859a39d74f1fe85e773ae4b)) - **sbom:** Improve depgraph for Maven projects ([fbb33d7](https://togithub.com/snyk/snyk/commit/fbb33d7e17f5866501abd4e4022e86eecb390415)) - **sbom:** Use RFC 3339 for all timestamps in sbom test result ([#​5204](https://togithub.com/snyk/snyk/issues/5204)) ([91bf191](https://togithub.com/snyk/snyk/commit/91bf1911997534c0bc2a6c0e093cf113f1292c49)) - **language-server:** Add --all-projects flag scans by default[#​5247](https://togithub.com/snyk/snyk/issues/5247)k/snyk/issues/5247\)) ([fdcf30e](https://togithub.com/snyk/snyk/commit/fdcf30e7421b7f8342d11003508f293661264a66)) - **language-server:** Enable incremental scanning[#​5291](https://togithub.com/snyk/snyk/issues/5291)k/snyk/issues/5291\)) ([d198685](https://togithub.com/snyk/snyk/commit/d1986856b152419e1712fa2c35b9b73303c428f9)) - **language-server:** Add support for IDE themes ([c1c4d08](https://togithub.com/snyk/snyk/commit/c1c4d0805252ee96c7e081edd6b4e42a23cee3b8)) - **language-server:** Consistent styling across intellij and vscode ([#​5282](https://togithub.com/snyk/snyk/issues/5282)) ([9aa6f76](https://togithub.com/snyk/snyk/commit/9aa6f76201661e8270a92ccc38c75285df435634)) - **logging:** Redact additional types of sensitive data from debug logs ([#​5254](https://togithub.com/snyk/snyk/issues/5254)) ([056cdab](https://togithub.com/snyk/snyk/commit/056cdab070102aec927db831090b5bb82df9d31e)) ##### Bug Fixes - **auth:** Autodetect IDE usage and fallback to API token based authentication ([#​5241](https://togithub.com/snyk/snyk/issues/5241)) ([4c795e0](https://togithub.com/snyk/snyk/commit/4c795e008e17386ac04466a45a9785e81258853b)) - **iac:** Upgrade iac custom rules to address Vulnerabilities[#​5191](https://togithub.com/snyk/snyk/issues/5191)yk/snyk/issues/5191\)) ([453db24](https://togithub.com/snyk/snyk/commit/453db24fb3fa8e58e4a69920ba18045ecbd650a2)) - **language-server:** Caching problem when no vulnerabilities in the IDE ([#​5223](https://togithub.com/snyk/snyk/issues/5223)) ([89c9491](https://togithub.com/snyk/snyk/commit/89c949162edd89d0553b6e6cbb1c14c62379eae9)) - **language-server:** Remove incorrect /v1 path ([#​5214](https://togithub.com/snyk/snyk/issues/5214)) ([cf16470](https://togithub.com/snyk/snyk/commit/cf16470090b6f1db7fd7f7577a243e4d356d843f)) - **dependencies:** Update dependencies to reduce vulnerabilities ([#​5131](https://togithub.com/snyk/snyk/issues/5131)) ([4c7cb3c](https://togithub.com/snyk/snyk/commit/4c7cb3cd0931e0b8717425ac4857b116cee001ee)) - **sbom:** sbom test output padding ([e3b7cac](https://togithub.com/snyk/snyk/commit/e3b7cac1b3fc628407e1ba520302f3569684d115)) - **sbom:** Fix container purl generation for apt and rpm ([#​5207](https://togithub.com/snyk/snyk/issues/5207)) ([fa9d512](https://togithub.com/snyk/snyk/commit/fa9d512512203adcdc133ed988ac260543f8816a)) - **sbom:** Retain error code during SBOM generation ([#​5202](https://togithub.com/snyk/snyk/issues/5202)) ([5e98aaa](https://togithub.com/snyk/snyk/commit/5e98aaa6b14fe2d3622a3cc1ce76b655f43bb42c)) - **test:** support cyclic dependencies in maven with dverbose ([#​5208](https://togithub.com/snyk/snyk/issues/5208)) ([fb24c02](https://togithub.com/snyk/snyk/commit/fb24c024a8bee69ae59acf79adfac7866255b2b7)) - **test:** Add tool version and informationUri to sarif output ([#​5203](https://togithub.com/snyk/snyk/issues/5203)) ([b899fd3](https://togithub.com/snyk/snyk/commit/b899fd3af211e8b95656a08b9b0ecefc086ef5d5)) - **test:** fixing several .NET bugs ([#​5217](https://togithub.com/snyk/snyk/issues/5217)) ([c27d767](https://togithub.com/snyk/snyk/commit/c27d7671c1c9d20089f10663b71875e6bcf05481)) - **test:** fixing a bug causing .NET beta scanning to fail on older versions of .NET ([#​5228](https://togithub.com/snyk/snyk/issues/5228)) ([5fdecf7](https://togithub.com/snyk/snyk/commit/5fdecf72e6f370bd31baadce6d1e5273018798c1)) - **test:** .NET runtime resolution testing now supports projects targeting .NET Standard frameworks ([#​5169](https://togithub.com/snyk/snyk/issues/5169)) ([44d0861](https://togithub.com/snyk/snyk/commit/44d0861e41de81f847c6b57c74a67c5fc816e9df)) - **test:** fix issues of type 'Cannot find module ...' in snyk-docker-plugin ([#​5301](https://togithub.com/snyk/snyk/issues/5301)) ([88efd54](https://togithub.com/snyk/snyk/commit/88efd549956513fd3052de8af47da5d0a1bfb477)) - **monitor:** fix project name when using assets-project-name flag ([#​5077](https://togithub.com/snyk/snyk/issues/5077)) ([57dc718](https://togithub.com/snyk/snyk/commit/57dc7189eb6c353041b8526af3fe939b0526d996)) ### [`v1.1291.1`](https://togithub.com/snyk/cli/releases/tag/v1.1291.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1291.0...v1.1291.1) The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see [this documentation](https://docs.snyk.io/snyk-cli/releases-and-channels-for-the-snyk-cli) ##### Bug Fixes - **dependencies:** Upgrade go-getter to v1.7.4 to fix vulnerabilities ([#​5252](https://togithub.com/snyk/snyk/issues/5252)) ### [`v1.1291.0`](https://togithub.com/snyk/cli/releases/tag/v1.1291.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1290.0...v1.1291.0) The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see [this documentation](https://docs.snyk.io/snyk-cli/releases-and-channels-for-the-snyk-cli) ##### News - This is the first **stable release** of the CLI - It makes use of semantic versioning and is the successor of [1.1290.0](https://togithub.com/snyk/cli/releases/tag/v1.1290.0) ##### Bug Fixes - **test:** Fix support of cyclic dependencies in maven with dverbose [#​5208](https://togithub.com/snyk/cli/pull/5208) ### [`v1.1290.0`](https://togithub.com/snyk/cli/releases/tag/v1.1290.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1289.0...v1.1290.0) ##### Bug Fixes - **code:** Fix error handling for experimental go native code client ([#​5170](https://togithub.com/snyk/snyk/issues/5170)) ([5400c69](https://togithub.com/snyk/snyk/commit/5400c698a2798672e96c91dd18706c2effebc416)) ##### Features - **code:** introduce human readable formatting for experimental test mechanism ([#​5174](https://togithub.com/snyk/snyk/issues/5174)) ([34bbc95](https://togithub.com/snyk/snyk/commit/34bbc955d241d619177dcdbf5f45bf02342e2adc)) - **sbom:** Introduce experimental sbom test command ([#​5176](https://togithub.com/snyk/snyk/issues/5176)) ([ea6293b](https://togithub.com/snyk/snyk/commit/ea6293b3adabd2459bb10a0ae65f78da8cf1311d)) - snyk woof ro language support and tests ([#​5166](https://togithub.com/snyk/snyk/issues/5166)) ([ed2e754](https://togithub.com/snyk/snyk/commit/ed2e754bace7a37f10a86564d5cf662f69e58daf)) ### [`v1.1289.0`](https://togithub.com/snyk/cli/releases/tag/v1.1289.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1288.1...v1.1289.0) ##### Bug Fixes - **ls:** Trigger re-analysis after fixing interfile issues ([#​5163](https://togithub.com/snyk/snyk/issues/5163)) ([05cb9f5](https://togithub.com/snyk/snyk/commit/05cb9f5ba9284999269368d1a0a98c8562f4badd)) ##### Features - **code:** Integrate experimental go native code client \[CLI-224] ([#​5164](https://togithub.com/snyk/snyk/issues/5164)) ([5bd898e](https://togithub.com/snyk/snyk/commit/5bd898e708dfb8caaa758debbf7d21998e9f2693)) - include additional policy properties, when provided, in plain text output ([#​5142](https://togithub.com/snyk/snyk/issues/5142)) ([a8be764](https://togithub.com/snyk/snyk/commit/a8be76486bfc17dda643d18a6fa9475744ddbd5c)) - use workflow data to determine exit code errors ([51c717b](https://togithub.com/snyk/snyk/commit/51c717b20c7eb8de1d2bca48c4d78ed530890b7c)) ### [`v1.1288.1`](https://togithub.com/snyk/cli/releases/tag/v1.1288.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1288.0...v1.1288.1) ##### Bug Fixes - **iac:** Fix Issue Path in human readable and json output \[IAC-2935] ([#​5159](https://togithub.com/snyk/snyk/issues/5159)) ([5fc3d59](https://togithub.com/snyk/snyk/commit/5fc3d591fefbcf0c5e7615bf4d9899a3a17c7990)) ### [`v1.1288.0`](https://togithub.com/snyk/cli/releases/tag/v1.1288.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1287.0...v1.1288.0) ##### Bug Fixes - add --experimental flag for snyk code test ([#​5151](https://togithub.com/snyk/snyk/issues/5151)) ([08647f2](https://togithub.com/snyk/snyk/commit/08647f295dd92ceb206a4f1b99e3b1905eab016e)) - make download of CLI in language server more resilient under windows \[IDE-90] ([#​5155](https://togithub.com/snyk/snyk/issues/5155)) ([1e51948](https://togithub.com/snyk/snyk/commit/1e5194853a3183629a9fad9679fc83e7b8d4d4cb)) ##### Features - bump language server protocol version to 11 \[IDE-236] ([#​5156](https://togithub.com/snyk/snyk/issues/5156)) ([fc41937](https://togithub.com/snyk/snyk/commit/fc41937f14f647e43e2b21b93ce3cc261a3de468)) ### [`v1.1287.0`](https://togithub.com/snyk/cli/releases/tag/v1.1287.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1286.4...v1.1287.0) ##### Features - upgrade snyk-iac-test to v0.51.3 ([#​5127](https://togithub.com/snyk/snyk/issues/5127)) ([0fd8fa6](https://togithub.com/snyk/snyk/commit/0fd8fa6063f35f208c36fdcbd04c8c4732d32af4)) ### [`v1.1286.4`](https://togithub.com/snyk/cli/releases/tag/v1.1286.4) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1286.3...v1.1286.4) ##### Bug Fixes - upgrade iac custom rules extension to address vulns \[IAC-2921] ([#​5149](https://togithub.com/snyk/snyk/issues/5149)) ([6b96473](https://togithub.com/snyk/snyk/commit/6b96473e3c07a93fdc5da2f10bb39ea6f5a222d7)) ### [`v1.1286.3`](https://togithub.com/snyk/cli/releases/tag/v1.1286.3) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1286.2...v1.1286.3) ##### Bug Fixes - always finish progress when auto-fixing in language server ([#​5145](https://togithub.com/snyk/snyk/issues/5145)) ([f645bbe](https://togithub.com/snyk/snyk/commit/f645bbe4b439a9523fcd16cc9857786bd25898b4)) - avoid potentially outputting very large JSON objects ([#​5147](https://togithub.com/snyk/snyk/issues/5147)) ([84b5e8b](https://togithub.com/snyk/snyk/commit/84b5e8bf390d4e68665c79efa57a4a7ed7cb3600)) ### [`v1.1286.2`](https://togithub.com/snyk/cli/releases/tag/v1.1286.2) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1286.1...v1.1286.2) ##### Bug Fixes - enhance sbt output width, fixing false positives vulns ([#​5130](https://togithub.com/snyk/snyk/issues/5130)) ([2011b90](https://togithub.com/snyk/snyk/commit/2011b90704582654560d6d64819fe8d3cdfc91fd)) ### [`v1.1286.1`](https://togithub.com/snyk/cli/releases/tag/v1.1286.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1286.0...v1.1286.1) ##### Bug Fixes - Fix error in sbom command when using --json-file-output ([#​5136](https://togithub.com/snyk/snyk/issues/5136)) ([eee1ec5](https://togithub.com/snyk/snyk/commit/eee1ec5fb73a55da2afbe2eb5a8dfc867942c77e)) ### [`v1.1286.0`](https://togithub.com/snyk/cli/releases/tag/v1.1286.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1285.1...v1.1286.0) ##### Features - support CycloneDX v1.5 ([#​5123](https://togithub.com/snyk/snyk/issues/5123)) ([b22b166](https://togithub.com/snyk/snyk/commit/b22b1667ff87d5a48f6b0d36a1f42f4cd67d0990)) ### [`v1.1285.1`](https://togithub.com/snyk/cli/releases/tag/v1.1285.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1285.0...v1.1285.1) ##### Bug Fixes - **ci:** add missing node types ([#​5129](https://togithub.com/snyk/snyk/issues/5129)) ([c55af61](https://togithub.com/snyk/snyk/commit/c55af61d0c76256605bf1f5780d9082f85a84120)) - Fix handling of large json data when using --json \[CLI-73] ([#​5093](https://togithub.com/snyk/snyk/issues/5093)) ([c0d401c](https://togithub.com/snyk/snyk/commit/c0d401c38742f4da593b680a53a509726f9e9717)) ### [`v1.1285.0`](https://togithub.com/snyk/cli/releases/tag/v1.1285.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1284.0...v1.1285.0) ##### Features - **language-server:** Added command to retrieve fix suggestions for snyk code - **language-server:** Added Feature Flag command - **language-server:** Associate learn lessons with all specified ecosystems ### [`v1.1284.0`](https://togithub.com/snyk/cli/releases/tag/v1.1284.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1283.1...v1.1284.0) ##### Features - support -dverbose argument when testing maven projects [#​5117](https://togithub.com/snyk/snyk/issues/5117) ([1ef091f](https://togithub.com/snyk/snyk/commit/1ef091fab322e03b51397633d88fb635b92ecb89)) ### [`v1.1283.1`](https://togithub.com/snyk/cli/releases/tag/v1.1283.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1283.0...v1.1283.1) ##### Bug Fixes - **ci:** End to end test by updating to a newer test image ([#​5115](https://togithub.com/snyk/snyk/issues/5115)) ([93b4fcb](https://togithub.com/snyk/snyk/commit/93b4fcb10b3768a59993b8ee29698b84fd8b1ef4)) - fix add support for dev/alpha/beta/rc python versions ([#​5106](https://togithub.com/snyk/snyk/issues/5106)) ([bd6351a](https://togithub.com/snyk/snyk/commit/bd6351aa33369407d22835460d6e2c0128f13cb4)), closes [#​5108](https://togithub.com/snyk/snyk/issues/5108) [#​5107](https://togithub.com/snyk/snyk/issues/5107) ### [`v1.1283.0`](https://togithub.com/snyk/cli/releases/tag/v1.1283.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1282.1...v1.1283.0) ##### Features - add python optional dependencies support ([#​5072](https://togithub.com/snyk/snyk/issues/5072)) ([e52fdaa](https://togithub.com/snyk/snyk/commit/e52fdaab6158ccf196c58b18e6665919376df982)) ### [`v1.1282.1`](https://togithub.com/snyk/cli/releases/tag/v1.1282.1) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1282.0...v1.1282.1) ##### Bug Fixes - **ci:** upgrade slack webhook ([#​5085](https://togithub.com/snyk/snyk/issues/5085)) ([9f4d512](https://togithub.com/snyk/snyk/commit/9f4d512c96401e4b163844ad5743f3ee244a999a)) - **danger:** commit pattern in danger to disable certain characters ([#​5089](https://togithub.com/snyk/snyk/issues/5089)) ([2113022](https://togithub.com/snyk/snyk/commit/211302214ad864a464dec78191f5cc0e3619b649)) - enforce correct type for security-severity in sarif output ([#​5091](https://togithub.com/snyk/snyk/issues/5091)) ([f0c8339](https://togithub.com/snyk/snyk/commit/f0c83391cb29c8f4eee190e953b0b7d357ae0cb7)) - remove dependencies when parent folder is deleted ([#​5080](https://togithub.com/snyk/snyk/issues/5080)) ([4f892f7](https://togithub.com/snyk/snyk/commit/4f892f75662f5898f035e16bbea697201afc0f33)) ### [`v1.1282.0`](https://togithub.com/snyk/cli/releases/tag/v1.1282.0) [Compare Source](https://togithub.com/snyk/snyk/compare/v1.1281.0...v1.1282.0) ##### Bug Fixes - enables multi-platform support for OCI images ([#​5082](https://togithub.com/snyk/snyk/issues/5082)) ([00af20b](https://togithub.com/snyk/snyk/commit/00af20b02234205e19231f975fc7b275bb3e37ab)) ##### Features - populate CVSS scores in SARIF files ([#​5014](https://togithub.com/snyk/snyk/issues/5014)) ([#​5088](https://togithub.com/snyk/snyk/issues/5088)) ([54253f7](https://togithub.com/snyk/snyk/commit/54253f748d5df0c8ac01971d994bc58eeac44aa0))

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

socket-security[bot] commented 6 months ago

Removed dependencies detected. Learn more about Socket for GitHub ↗︎

🚮 Removed packages: npm/@snyk/protect@1.1281.0

View full report↗︎