Skip to content

chore(deps-dev): bump snyk from 1.1307.0 to 1.1307.2 - #9178

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot-npm_and_yarn-develop-snyk-1.1307.2
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot-npm_and_yarn-develop-snyk-1.1307.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps snyk from 1.1307.0 to 1.1307.2.

Release notes

Sourced from snyk's releases.

v1.1307.2

1.1307.2 (2026-09-09)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

v1.1307.1

1.1307.1 (2026-09-07)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

  • test: snyk test on a repository with no supported manifest files again reports SNYK-CLI-0008 and exits 3, instead of a generic SNYK-CLI-0000 with exit 2. snyk test --json writes the error document to stdout as expected. (50cad38)
  • test: Restores moduleName, insights.triageAdvice, and functions_new fields in snyk test --json output. (4ec3d18)
  • test: .snyk policy files are now handled correctly in the unified test flow -- empty, whitespace-only and comment-only policies, date-only timestamps, and other edge cases that previously caused incorrect results or failures. (a22a563)
  • general: Fixes a case where CLI commands that complete with findings (exit 1) could produce duplicate or corrupt JSON output when an unrelated network error occurred during the run. (836ee0d)
  • general: Fixes debug-log scrubber so that secrets are consistently masked and scrubbing no longer corrupts the surrounding JSON structure. (d89333a)
  • container: Container scans now surface source repository information for locally built images using BuildKit metadata. (dd6ff36)
  • deps: Updates dependencies to fix vulnerabilities:
Commits
  • 0fda34a Merge pull request #7246 from snyk/hotfix/v1.1307.2
  • cff0212 docs: update RELEASE_NOTES.md
  • e045397 fix: bump gRPC dependency to fix CVE-2026-84445
  • ad487e9 fix: remove daemon initializer from private CLI build
  • db8ab37 Merge pull request #7233 from snyk/release/1.1307
  • e0bc724 Merge pull request #7232 from snyk/release-candidate
  • e5eb3e5 Merge pull request #7228 from snyk/chore/cherry-pick-hotfix-1.1307.1
  • 57ba3e6 Merge pull request #7231 from snyk/docs/automatic-gitbook-update-cli-help-cho...
  • 082d692 docs: synchronizing help from snyk/user-docs
  • 7722213 chore: Update Release Notes
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [snyk](https://github.com/snyk/snyk) from 1.1307.0 to 1.1307.2.
- [Release notes](https://github.com/snyk/snyk/releases)
- [Commits](snyk/cli@v1.1307.0...v1.1307.2)

---
updated-dependencies:
- dependency-name: snyk
  dependency-version: 1.1307.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 14, 2026
@coderabbitai

coderabbitai Bot commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Ignore keyword(s) in the title.

⛔ Ignored keywords (2)
  • chore
  • bump

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 52be5fcc-38c0-44b7-ac8c-1358d0f2cd48

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@BKSteve BKSteve mentioned this pull request Sep 16, 2026
3 tasks
@dependabot @github

dependabot Bot commented on behalf of github Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Looks like snyk is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 16, 2026
@dependabot
dependabot Bot deleted the dependabot-npm_and_yarn-develop-snyk-1.1307.2 branch September 16, 2026 04:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant