Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 19, 2026

Bumps @snyk/protect from 1.1300.0 to 1.1302.0.

Release notes

Sourced from @​snyk/protect's releases.

v1.1302.0

1.1302.0 (2026-01-14)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Features

  • aibom: Improved Exit Code handling (d8fed82)
  • container: Added support for OCI images with manifests missing platform fields (dae56aa)
  • container: Added container scan support for cgo and stripped Go binaries (9b2ee6e)
  • container: Added pnpm lockfile support (47db111)
  • mcp-scan: Added experimental mcp-scan command (54b8376)
  • sbom: Improved PackageURLs in SBOM documents for go.mod projects (c145efc)
  • sbom test: Added support for deb, apk and rpm (9fd6f84)
  • test: Added PackageURL information to go.mod dependency graphs (d90b54e)
  • test: Added support for poetry development dependencies (6977004)

Bug Fixes

  • container: Resolves false positive vulnerabilities for RHEL 10 container images (d4afe60)
  • general: Upgraded multiple dependencies (e185c92)
  • general: Fixed Exit Code handling when using incompatible glibc versions (66fbb50)
  • general: Improved file filtering support with .gitignore (a16b853)
  • mcp: Added rule file to .gitignore if not previously ignored (cc78694)
  • test: Improved upload speed when using --reachability (da21315)
  • test: Fixed npm v2 dependency resolution when using shadowing aliases (237a4f5)
  • test: Fixed --exclude support for pnpm workspaces (293d9b1)
  • test: Fixed SARIF output for Gradle projects to include the complete path in artifactLocation (ec1262e)

v1.1301.2

1.1301.2 (2025-12-16)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

  • mcp: Fix MCP compliance issue (51d3f8d)

v1.1301.1

1.1301.1 (2025-12-08)

The Snyk CLI is being deployed to different deployment channels, users can select the stability level according to their needs. For details please see this documentation

Bug Fixes

  • test: Rendering of fix advice for multiple dependency paths when using the reachability flag (eaf50bb)
  • monitor: snyk monitor --reachability=true command should now work even if double dashed arguments are provided (e8bdac6)
  • test, monitor: Code upload speed will be improved when running snyk test --reachability/snyk monitor --reachability (d0bdba1)
  • language-server: Multiple Snyk Language Server related fixes (485ae55)
  • dependencies: Upgrade dependencies to address multiple issues. (e185c92)

... (truncated)

Commits
  • cac06fc Merge pull request #6429 from snyk/chore/update_rc_1.1302.0
  • f796fd4 docs: synchronizing help from snyk/user-docs
  • 5b0fe92 fix: sbom test experimental flag backwards compatibility
  • 74baf5a Merge pull request #6423 from snyk/cn-612-find-pnpm-dependencies
  • 9baeb09 fix: linting
  • 114044d fix: update test to look for vulns in vuln module name
  • 1c46720 fix: test where the package is
  • 808238e fix: add test coverage for pnpm sub-dependencies
  • 45dccd5 fix: update snyk-docker-plugin, find pnpm sub-dependencies
  • 25c4570 Merge pull request #6421 from snyk/tmp/1767895586-release-candidate
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@snyk/protect](https://github.com/snyk/snyk) from 1.1300.0 to 1.1302.0.
- [Release notes](https://github.com/snyk/snyk/releases)
- [Commits](snyk/cli@v1.1300.0...v1.1302.0)

---
updated-dependencies:
- dependency-name: "@snyk/protect"
  dependency-version: 1.1302.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jan 19, 2026
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 26, 2026

Superseded by #391.

@dependabot dependabot bot closed this Jan 26, 2026
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/snyk/protect-1.1302.0 branch January 26, 2026 04:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants