chore(deps): update dependency snyk to v1.1064.0 [security]#425
Open
renovate[bot] wants to merge 1 commit intomasterfrom
Open
chore(deps): update dependency snyk to v1.1064.0 [security]#425renovate[bot] wants to merge 1 commit intomasterfrom
renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
Author
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: package-lock.json |
ec36ba5 to
958121f
Compare
958121f to
bbb5da6
Compare
bbb5da6 to
ed56878
Compare
ed56878 to
758fb5e
Compare
d7a0281 to
1771024
Compare
1771024 to
6707d0f
Compare
5003acb to
9353a27
Compare
6fe31af to
061482e
Compare
10a3f25 to
eecde8a
Compare
eecde8a to
fa242d9
Compare
3ce8617 to
427cc8a
Compare
51be271 to
8cbc54d
Compare
8cbc54d to
c294960
Compare
af1092f to
fd9939a
Compare
fd9939a to
cb79120
Compare
cb79120 to
93fce0c
Compare
93fce0c to
277eb16
Compare
a966067 to
beed77d
Compare
beed77d to
7668814
Compare
7668814 to
7323560
Compare
1a8c184 to
142072d
Compare
142072d to
2229c65
Compare
2229c65 to
40f34cf
Compare
40f34cf to
4cceaf1
Compare
4cceaf1 to
eb82c21
Compare
eb82c21 to
29fe2e7
Compare
29fe2e7 to
2965c05
Compare
2965c05 to
07a4567
Compare
07a4567 to
554ff09
Compare
554ff09 to
5c76b6a
Compare
5c76b6a to
abb6f13
Compare
|
Code Climate has analyzed commit abb6f13 and detected 0 issues on this pull request. View more on Code Climate. |
abb6f13 to
96f75ad
Compare
96f75ad to
a415fbd
Compare
a415fbd to
2231805
Compare
2231805 to
b82ee5a
Compare
b82ee5a to
63d6a4f
Compare
63d6a4f to
a198dbe
Compare
a198dbe to
2076d4b
Compare
2076d4b to
d646cf8
Compare
c691bf8 to
cb2cbb8
Compare
cb2cbb8 to
cac94f6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.946.0→1.1064.0GitHub Vulnerability Alerts
CVE-2022-40764
Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the Visual Studio Code editor, for example. The original demonstration was with shell metacharacters in the vendor.json ignore field, affecting snyk-go-plugin before 1.19.1. This affects, for example, the Snyk TeamCity plugin (which does not update automatically) before 20220930.142957.
CVE-2022-22984
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5; the package @snyk/snyk-hex-plugin before 1.1.6 are vulnerable to Command Injection due to an incomplete fix for CVE-2022-40764. A successful exploit allows attackers to run arbitrary commands on the host system where the Snyk CLI is installed by passing in crafted command line flags. In order to exploit this vulnerability, a user would have to execute the snyk test command on untrusted files. In most cases, an attacker positioned to control the command line arguments to the Snyk CLI would already be positioned to execute arbitrary commands. However, this could be abused in specific scenarios, such as continuous integration pipelines, where developers can control the arguments passed to the Snyk CLI to leverage this component as part of a wider attack against an integration/build pipeline. This issue has been addressed in the latest Snyk Docker images available at https://hub.docker.com/r/snyk/snyk as of 2022-11-29. Images downloaded and built prior to that date should be updated. The issue has also been addressed in the Snyk TeamCity CI/CD plugin as of version v20221130.093605.
CVE-2022-24441
The package snyk before 1.1064.0 is vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, which will be executed with the privileges of the application. This vulnerability may be triggered when running the the CLI tool directly, or when running a scan with one of the IDE plugins that invoke the Snyk CLI. Successful exploitation of this issue would likely require some level of social engineering - to coerce an untrusted project to be downloaded and analyzed via the Snyk CLI or opened in an IDE where a Snyk IDE plugin is installed and enabled. Additionally, if the IDE has a Trust feature then the target folder must be marked as ‘trusted’ in order to be vulnerable.
NOTE: This issue is independent of the one reported in CVE-2022-40764, and upgrading to a fixed version for this addresses that issue as well.
The affected IDE plugins and versions are:
Release Notes
snyk/snyk (snyk)
v1.1064.0Compare Source
Bug Fixes
v1.1063.0Compare Source
Features
v1.1062.0Compare Source
Bug Fixes
v1.1061.0Compare Source
Features
v1.1060.0Compare Source
Bug Fixes
v1.1059.0Compare Source
Bug Fixes
v1.1058.0Compare Source
Features
v1.1057.0Compare Source
v1.1056.0Compare Source
Bug Fixes
v1.1055.0Compare Source
Bug Fixes
v1.1054.0Compare Source
Bug Fixes
v1.1053.0Compare Source
Bug Fixes
v1.1052.0Compare Source
Features
v1.1051.0Compare Source
Bug Fixes
v1.1050.0Compare Source
Bug Fixes
v1.1049.0Compare Source
Features
v1.1048.0Compare Source
Bug Fixes
v1.1047.0Compare Source
v1.1046.0Compare Source
Bug Fixes
v1.1045.0Compare Source
Bug Fixes
Features
v1.1044.0Compare Source
Bug Fixes
Features
v1.1043.0Compare Source
Bug Fixes
v1.1042.0Compare Source
Bug Fixes
Features
v1.1041.0Compare Source
Bug Fixes
v1.1040.0Compare Source
Bug Fixes
v1.1039.0Compare Source
Features
v1.1038.0Compare Source
Features
v1.1037.0Compare Source
Bug Fixes
v1.1036.0Compare Source
What's Changed
Full Changelog: snyk/cli@v1.1035.0...v1.1036.0
v1.1035.0Compare Source
Features
v1.1034.0Compare Source
Features
v1.1033.0Compare Source
Features
v1.1032.0Compare Source
Features
v1.1031.0Compare Source
Bug Fixes
v1.1030.0Compare Source
Features
v1.1029.0Compare Source
v1.1028.0Compare Source
v1.1027.0Compare Source
Features
v1.1026.0Compare Source
Bug Fixes
v1.1025.0Compare Source
Features
v1.1024.0Compare Source
v1.1023.0Compare Source
Bug Fixes
v1.1022.0Compare Source
Bug Fixes
Features
v1.1021.0Compare Source
Bug Fixes
Features
v1.1020.0Compare Source
v1.1019.0Compare Source
Bug Fixes
Features
v1.1018.0Compare Source
Features
v1.1017.0Compare Source
Features
v1.1016.0Compare Source
Bug Fixes
v1.1015.0Compare Source
Features
v1.1014.0Compare Source
Features
v1.1013.0Compare Source
Features
v1.1012.0Compare Source
Features
v1.1011.0Compare Source
Bug Fixes
v1.1010.0Compare Source
Bug Fixes
v1.1009.0Compare Source
v1.1008.0Compare Source
v1.1007.0Compare Source
Bug Fixes
Features
v1.1006.0Compare Source
Features
v1.1005.0Compare Source
Bug Fixes
Features
v1.1004.0Compare Source
Features
v1.1003.0Compare Source
Bug Fixes
Features
v1.1002.0Compare Source
Features
v1.1001.0Compare Source
Features
v1.1000.0Compare Source
Bug Fixes
v1.999.0Compare Source
Features
v1.998.0Compare Source
Features
v1.997.0Compare Source
Bug Fixes
v1.996.0Compare Source
Bug Fixes
Features
v1.995.0Compare Source
Bug Fixes
v1.994.0Compare Source
Bug Fixes
Features
v1.993.0Compare Source
Features
v1.992.0Compare Source
Bug Fixes
--target-namebug (3431f79)v1.991.0Compare Source
Features
v1.990.0Compare Source
Bug Fixes
v1.989.0Compare Source
Bug Fixes
Features
v1.988.0Compare Source
Bug Fixes
Features
v1.987.0Compare Source
Bug Fixes
Features
v1.986.0Compare Source
Bug Fixes
v1.985.0Compare Source
Bug Fixes
Features
v1.984.0Compare Source
v1.983.0Compare Source
Bug Fixes
Features
v1.982.0Compare Source
Bug Fixes
Features
v1.981.0Compare Source
Bug Fixes
v1.980.0Compare Source
Features
v1.979.0Compare Source
Bug Fixes
v1.978.0Compare Source
Features
v1.977.0Compare Source
Bug Fixes
Features
v1.976.0Compare Source
Features
v1.975.0Compare Source
Features
v1.974.0Compare Source
Features
v1.973.0Compare Source
Bug Fixes
Features
v1.972.0Compare Source
Bug Fixes
Features
v1.971.0Compare Source
Features
v1.970.0Compare Source
v1.969.0Compare Source
Features
v1.968.0Compare Source
Features
v1.967.0Compare Source
Bug Fixes
v1.966.0Compare Source
Bug Fixes
v1.965.0Compare Source
Bug Fixes
v1.964.0Compare Source
Features
v1.963.0Compare Source
Bug Fixes
v1.962.0Compare Source
Bug Fixes
Features
v1.961.0Compare Source
Bug Fixes
v1.960.0Compare Source
Bug Fixes
v1.959.0Compare Source
Bug Fixes
Features
v1.958.0Compare Source
Bug Fixes
v1.957.0Compare Source
Bug Fixes
v1.956.0Compare Source
Bug Fixes
v1.955.0Compare Source
Bug Fixes
Features
v1.954.0Compare Source
Features
v1.953.0Compare Source
Features
v1.952.0Compare Source
Bug Fixes
v1.951.0Compare Source
Features
v1.950.0Compare Source
Features
v1.949.0Compare Source
Bug Fixes
v1.948.0Compare Source
Features
v1.947.0Compare Source
Bug Fixes
Features
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.