Skip to content

chore: update main 1.1307.2 - #7252

Merged
octavian-snyk merged 6 commits into
mainfrom
chore/update_main_1.1307.2
Sep 10, 2026
Merged

chore: update main 1.1307.2#7252
octavian-snyk merged 6 commits into
mainfrom
chore/update_main_1.1307.2

Conversation

@PeterSchafer

@PeterSchafer PeterSchafer commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Where should the reviewer start?

How should this be manually tested?

What's the product update that needs to be communicated to CLI users?


Note

Low Risk
Patch-level indirect dependency bump with no application code changes; typical low-risk maintenance.

Overview
Bumps the indirect google.golang.org/grpc dependency from v1.83.1 to v1.83.2 in both cliv2 and cliv2-private, with matching go.sum checksum updates. There are no source or behavioral changes in this PR—only module lockfile maintenance, likely as part of the 1.1307.2 release sync.

Reviewed by Cursor Bugbot for commit f1f0aa3. Bugbot is set up for automated code reviews on this repo. Configure here.

cursoragent and others added 5 commits September 9, 2026 13:59
The daemon extension (github.com/snyk/ambient-canary) exposed an
unauthenticated local HTTP endpoint that could be reached from a
browser via a CORS simple request, allowing arbitrary CLI command
execution without folder trust. It was only intended for internal
testing and was never documented or announced. Remove the
extension registration until a threat model review is completed.

Co-authored-by: Bastian Doetsch <bastian.doetsch@snyk.io>
chore: sync 1.1307.2 into release-candidate
@PeterSchafer
PeterSchafer requested a review from a team as a code owner September 9, 2026 15:20
@snyk-io

snyk-io Bot commented Sep 9, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@snyk-pr-review-bot

This comment has been minimized.

@octavian-snyk
octavian-snyk force-pushed the chore/update_main_1.1307.2 branch from 5fac419 to f1f0aa3 Compare September 10, 2026 06:09
@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 5 relevant code sections from 5 files (average relevance: 0.80)

🤖 Repository instructions applied (from AGENTS.md)

@github-actions

Copy link
Copy Markdown
Contributor
Warnings
⚠️ There are multiple commits on your branch, please squash them locally before merging!
⚠️

"Merge remote-tracking branch 'origin/main' into chore/update_main_1.1307.2" is too long. Keep the first line of your commit message under 72 characters.

Generated by 🚫 dangerJS against f1f0aa3

@octavian-snyk
octavian-snyk merged commit 3fccfba into main Sep 10, 2026
10 of 11 checks passed
@octavian-snyk
octavian-snyk deleted the chore/update_main_1.1307.2 branch September 10, 2026 07:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants