[Snyk] Upgrade snyk from 1.278.1 to 1.1306.1 - #1639
Open
dragos-cojocari wants to merge 1 commit into
Open
Conversation
Author
|
This is a significant upgrade, spanning hundreds of individual releases. While there are no major breaking API changes for core commands like Key Changes:
Recommendation: Due to the changes in logging and exit behavior, it is recommended to test and verify any CI/CD scripts that rely on the Snyk CLI's specific output or exit codes before merging. Source: Snyk CLI GitHub Releases
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade snyk from 1.278.1 to 1.1306.1.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 1223 versions ahead of your current version.
The recommended version was released 22 days ago.
Issues fixed by the recommended upgrade:
SNYK-JS-IP-6240864
SNYK-JS-LODASHSET-1320032
SNYK-JS-PARSEPATH-2936439
SNYK-JS-NCONF-2395478
SNYK-JS-NETMASK-1089716
SNYK-JS-NETMASK-6056519
SNYK-JS-PACRESOLVER-1564857
SNYK-JS-IP-12761655
SNYK-JS-SNYKGRADLEPLUGIN-8248487
SNYK-JS-TMP-17315641
SNYK-JS-TMP-17315641
SNYK-JS-DOTPROP-543489
SNYK-JS-IP-7148531
SNYK-JS-JSZIP-1251497
SNYK-JS-JSZIP-3188562
SNYK-JS-PARSEURL-2935944
SNYK-JS-PARSEURL-2935947
SNYK-JS-PARSEURL-2936249
SNYK-JS-IP-12704893
SNYK-JS-TMP-16881240
SNYK-JS-TMP-16881240
SNYK-JS-SNYKPHPPLUGIN-8248485
SNYK-JS-PARSEURL-2942134
SNYK-JS-PARSEURL-3023021
SNYK-JS-PARSEURL-3024398
SNYK-JS-SNYK-3038622
SNYK-JS-SNYK-3111871
SNYK-JS-SNYKDOCKERPLUGIN-3039679
SNYK-JS-SNYKGRADLEPLUGIN-3038624
SNYK-JS-SNYKMVNPLUGIN-3038623
SNYK-JS-SNYKPYTHONPLUGIN-3039677
SNYK-JS-SNYKSBTPLUGIN-3038626
SNYK-JS-SNYKSNYKCOCOAPODSPLUGIN-3038625
SNYK-JS-TMP-11501554
SNYK-JS-TMP-11501554
SNYK-JS-SNYKGOPLUGIN-3037316
SNYK-JS-SNYK-3037342
SNYK-JS-SNYK-10497607
SNYK-JS-WORDWRAP-3149973
Breaking Change Risk
Release notes
Package name: snyk
1.1306.1 (2026-07-16)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their
needs. For details please see this documentation
Bug Fixes
CVE-2026-59869 (7673263)
CVE-2026-39244 (9bf7ce7)
1.1306.0 (2026-07-09)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
snyk doctorcommand to diagnose common CLI problems: generate a diagnostic report for the current system, or analyze debug log output. (ab56a0e)snyk redteamcommand has been removed from the CLI, following its deprecation (deprecation date May 31, 2026). (c7d0e3e)Bug Fixes
1.1305.2 (2026-06-23)
Bug Fixes
1.1305.1 (2026-06-02)
Bug Fixes
X-RateLimit-Resetheader. (2e690df)1.1305.0 (2026-05-20)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
--allow-incomplete-sbomflag forsnyk sbom, allowing the SBOM to be generated even when individual projects fail to resolve. Failed projects are surfaced as per-project errors alongside the successful results. (29ba128)snyk container monitorby sending dependency requests in parallel, configurable via theSNYK_REQUEST_CONCURRENCYenvironment variable. (186c5fb, 6764f65)Bug Fixes
.whlfiles when scanning projects with--all-projects. (12ac0db)1.1304.3 (2026-05-13)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
Known Issues
snyk/snykcontainer images via the transitivegithub.qkg1.top/gomarkdown/markdowndependency (SNYK-GOLANG-GITHUBCOMGOMARKDOWNMARKDOWNHTML-16066911, SNYK-GOLANG-GITHUBCOMGOMARKDOWNMARKDOWNPARSER-8220052). We have assessed these vulnerabilities and confirmed they do not impact CLI users. A fix is scheduled for the stable release on2026-05-20.1.1304.2 (2026-05-06)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
1.1304.1 (2026-04-27)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes