Skip to content

chore: bump GAF (SARIF to UFM) - #7240

Open
octavian-snyk wants to merge 1 commit into
mainfrom
chore/CLI-1837
Open

chore: bump GAF (SARIF to UFM)#7240
octavian-snyk wants to merge 1 commit into
mainfrom
chore/CLI-1837

Conversation

@octavian-snyk

@octavian-snyk octavian-snyk commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Where should the reviewer start?

How should this be manually tested?

What's the product update that needs to be communicated to CLI users?

None

What are the relevant tickets?

CLI-1837


Note

Medium Risk
GAF is core CLI infrastructure; a version bump can change output formats, workflows, and exit-code handling even without local code edits.

Overview
Updates github.com/snyk/go-application-framework from v0.23.0 to pre-release v0.23.1-0.20260908131323-e6578970bb8c in cliv2 (direct require) and cliv2-private (transitive), with matching go.sum checksum updates.

There are no CLI source changes in this PR—the behavior shift comes from the new GAF version, aligned with ticket CLI-1837 and the SARIF → UFM work referenced in the title. Reviewers should treat this as consuming upstream GAF output/workflow changes rather than reviewing new logic in this repo.

Reviewed by Cursor Bugbot for commit f7557db. Bugbot is set up for automated code reviews on this repo. Configure here.

@octavian-snyk
octavian-snyk requested a review from a team as a code owner September 8, 2026 08:59
@snyk-io

snyk-io Bot commented Sep 8, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 No relevant tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 4 relevant code sections from 3 files (average relevance: 0.94)

🤖 Repository instructions applied (from AGENTS.md)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant