Skip to content

chore: sync main with rc - #7253

Open
octavian-snyk wants to merge 6 commits into
mainfrom
chore/sync-main-with-rc
Open

chore: sync main with rc#7253
octavian-snyk wants to merge 6 commits into
mainfrom
chore/sync-main-with-rc

Conversation

@octavian-snyk

@octavian-snyk octavian-snyk commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Pull Request Submission Checklist

  • Follows CONTRIBUTING guidelines
  • Commit messages
    are release-note ready, emphasizing
    what was changed, not how.
  • Includes detailed description of changes
  • Contains risk assessment (Low | Medium | High)
  • Highlights breaking API changes (if applicable)
  • Links to automated tests covering new functionality
  • Includes manual testing instructions (if necessary)
  • Updates relevant GitBook documentation (PR link: ___)
  • Includes product update to be announced in the next stable release notes

What does this PR do?

Where should the reviewer start?

How should this be manually tested?

What's the product update that needs to be communicated to CLI users?


Note

Low Risk
Patch-level indirect dependency bump with no CLI code changes; typical low-risk dependency maintenance.

Overview
Bumps the indirect google.golang.org/grpc dependency from v1.83.1 to v1.83.2 in both cliv2 and cliv2-private, with matching go.sum checksum updates. No application source changes—only module lockfile alignment, consistent with syncing branches.

Reviewed by Cursor Bugbot for commit 42e9c02. Bugbot is set up for automated code reviews on this repo. Configure here.

cursoragent and others added 6 commits September 9, 2026 13:59
The daemon extension (github.com/snyk/ambient-canary) exposed an
unauthenticated local HTTP endpoint that could be reached from a
browser via a CORS simple request, allowing arbitrary CLI command
execution without folder trust. It was only intended for internal
testing and was never documented or announced. Remove the
extension registration until a threat model review is completed.

Co-authored-by: Bastian Doetsch <bastian.doetsch@snyk.io>
chore: sync 1.1307.2 into release-candidate
@octavian-snyk
octavian-snyk requested a review from a team as a code owner September 9, 2026 16:50
@octavian-snyk octavian-snyk changed the title Chore/sync main with rc chore: sync main with rc Sep 9, 2026
@snyk-io

snyk-io Bot commented Sep 9, 2026

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@snyk-pr-review-bot

Copy link
Copy Markdown

PR Reviewer Guide 🔍

🧪 PR contains tests
🔒 No security concerns identified
⚡ No major issues detected
📚 Repository Context Analyzed

This review considered 6 relevant code sections from 4 files (average relevance: 0.81)

🤖 Repository instructions applied (from AGENTS.md)

@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor
Warnings
⚠️ There are multiple commits on your branch, please squash them locally before merging!
⚠️

"Merge remote-tracking branch 'origin/release-candidate' into chore/sync-main-with-rc" is too long. Keep the first line of your commit message under 72 characters.

Generated by 🚫 dangerJS against 42e9c02

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants