[Snyk] Upgrade snyk from 1.667.0 to 1.1301.2#339
Conversation
Snyk has created this PR to upgrade snyk from 1.667.0 to 1.1301.2. See this package in npm: snyk See this project in Snyk: https://app.snyk.io/org/mikr13/project/57521539-278b-42e8-9b34-51cc78f04622?utm_source=github&utm_medium=referral&page=upgrade-pr
There was a problem hiding this comment.
Pull request overview
This pull request upgrades the Snyk CLI from version 1.667.0 to 1.1301.2, a jump of 669 versions. The upgrade addresses 58 security vulnerabilities across high, medium, and low severity levels, including issues like ReDoS, prototype pollution, command injection, and CSRF vulnerabilities.
Changes:
- Updates the
snykdevDependency version in package.json from ^1.742.0 to ^1.1301.2
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| }, | ||
| "devDependencies": { | ||
| "snyk": "^1.742.0" | ||
| "snyk": "^1.1301.2" |
There was a problem hiding this comment.
The package-lock.json file shows snyk version 1.1302.0 is installed, but package.json specifies version ^1.1301.2. This version mismatch between package.json and package-lock.json should be resolved. The lock file should be regenerated to match the intended version specified in package.json, or package.json should be updated to reflect the actual installed version.
| "snyk": "^1.1301.2" | |
| "snyk": "^1.1302.0" |
Snyk has created this PR to upgrade snyk from 1.667.0 to 1.1301.2.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 669 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-PARSELINKHEADER-1582783
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-ANSIREGEX-1583908
SNYK-JS-ASYNC-2441827
SNYK-JS-AXIOS-1579269
SNYK-JS-AXIOS-6032459
SNYK-JS-SEMVER-3247795
SNYK-JS-SEMVER-3247795
SNYK-JS-SEMVER-3247795
SNYK-JS-BRACES-6838727
SNYK-JS-CROSSSPAWN-8303230
SNYK-JS-CROSSSPAWN-8303230
SNYK-JS-SNYKGRADLEPLUGIN-8248487
SNYK-JS-SNYKPHPPLUGIN-8248485
SNYK-JS-FOLLOWREDIRECTS-6141137
SNYK-JS-LODASHSET-1320032
SNYK-JS-SSH2-1656673
SNYK-JS-TAR-1579152
SNYK-JS-TAR-1579155
SNYK-JS-UTILE-8706797
SNYK-JS-AXIOS-12613773
SNYK-JS-AXIOS-6124857
SNYK-JS-SNYK-3037342
SNYK-JS-SNYK-3038622
SNYK-JS-SNYK-3111871
SNYK-JS-AXIOS-9292519
SNYK-JS-AXIOS-9403194
SNYK-JS-FOLLOWREDIRECTS-2332181
SNYK-JS-SNYKDOCKERPLUGIN-3039679
SNYK-JS-SNYKGOPLUGIN-3037316
SNYK-JS-SNYKGRADLEPLUGIN-3038624
SNYK-JS-SNYKMVNPLUGIN-3038623
SNYK-JS-SNYKPYTHONPLUGIN-3039677
SNYK-JS-SNYKSBTPLUGIN-3038626
SNYK-JS-SNYKSNYKCOCOAPODSPLUGIN-3038625
SNYK-JS-SNYKSNYKHEXPLUGIN-3039680
SNYK-JS-FOLLOWREDIRECTS-6444610
SNYK-JS-GOT-2932019
SNYK-JS-GOT-2932019
SNYK-JS-HTTPCACHESEMANTICS-3248783
SNYK-JS-I-1726768
SNYK-JS-INFLIGHT-6095116
SNYK-JS-JSYAML-13961110
SNYK-JS-JSYAML-13961110
SNYK-JS-JSZIP-3188562
SNYK-JS-JSZIP-3188562
SNYK-JS-TAR-6476909
SNYK-JS-TMP-11501554
SNYK-JS-TMP-11501554
SNYK-JS-TMP-11501554
SNYK-JS-MICROMATCH-6838728
SNYK-JS-MICROMATCH-6838728
SNYK-JS-MINIMATCH-3050818
SNYK-JS-XML2JS-5414874
SNYK-JS-SNYK-10497607
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-FOLLOWREDIRECTS-2396346
npm:utile:20180614
Release notes
Package name: snyk
1.1301.2 (2025-12-16)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
1.1301.1 (2025-12-08)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
reachabilityflag (eaf50bb)snyk monitor --reachability=truecommand should now work even if double dashed arguments are provided (e8bdac6)snyk test --reachability/snyk monitor --reachability(d0bdba1)1.1301.0 (2025-11-12)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
--include-system-jars, to support scanning of usr/lib JARs (57078b6)--include-provenancethat will produce DepGraphs containing purls with checksum qualifiers for each package. Primarily to be used via --print-graph, not yet used in the main testing flow (5b8fe0a)--include-provenancethat will produce an SBOM with checksum qualifiers in each purl (5b8fe0a)Bug Fixes
(bfcbda7)
1.1300.2 (2025-10-28)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
1.1300.1 (2025-10-21)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
Bug Fixes
1.1300.0 (2025-10-08)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Features
Bug Fixes
1.1299.1 (2025-09-24)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
Bug Fixes
1.1299.0 (2025-08-28)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation.
Features
Bug Fixes
code test --reportwhen aproject_idenvironment variable exists. (6168b1d)snyk code testwhere an empty input parameter would cause inconsistent behavior. (a661235)CVE-2025-8959. (5a548fb)project.assets.jsonfiles would not be detected in cases where it's destination path was altered with .NET properties. (75a152e)--all-projects. (960fa8e)1.1298.3 (2025-08-14)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
News
aibom: This command is now publicly available. Note that the feature is still experimental and subject to breaking changes without notice.
Effective with release (Snyk CLI 1.1298.0), the minimum required GNU C Library (glibc) versions on Linux will be updated as follows:
If this affects you, please follow the advice here. Possible issues are errors mentioning
GLIBC_2.27orGLIBC_2.31not found.Bug Fixes
1.1298.2 (2025-07-30)
The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation
News
GLIBC_2.27orGLIBC_2.31not found.Bug Fixes