-
Notifications
You must be signed in to change notification settings - Fork 3.8k
[Snyk] Upgrade @vscode/ripgrep from 1.15.9 to 1.17.0 #8870
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Snyk has created this PR to upgrade @vscode/ripgrep from 1.15.9 to 1.17.0. See this package in npm: @vscode/ripgrep See this project in Snyk: https://app.snyk.io/org/continue-dev-inc.-default/project/7ff64b12-9373-49d8-a6a5-70de1609223c?utm_source=github&utm_medium=referral&page=upgrade-pr
|
|
✅ Review Complete Code Review Summary |
|
This PR upgrades the @vscode/ripgrep dependency to address security vulnerabilities. Since this is a version bump of an external package with no code changes, the existing test suite provides adequate coverage to validate compatibility with the new version. No additional tests are needed. |
|
Reviewed the PR changes - this is an internal dependency security upgrade that doesn't require documentation updates. The ripgrep version is not exposed to users and there are no user-facing feature changes or configuration updates needed. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
No issues found across 1 file
…nyk-upgrade-ea160fcc3b1079e3fb39a7b3e0f5d3e7
|
seems to break build script |
Snyk has created this PR to upgrade @vscode/ripgrep from 1.15.9 to 1.17.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 5 versions ahead of your current version.
The recommended version was released a month ago.
Issues fixed by the recommended upgrade:
SNYK-JS-GLOB-14040952
SNYK-JS-AXIOS-12613773
SNYK-JS-JSYAML-13961110
SNYK-JS-VITE-13644406
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-BRACEEXPANSION-9789073
SNYK-JS-VITE-12558116
Release notes
Package name: @vscode/ripgrep
-
1.17.0 - 2025-10-21
- #79: 1.17.0
- #78: chore: bump prebuilt to v15.0.0
- #77: 1.16.0
-
1.15.14 - 2025-06-27
- #74: 1.15.14
- #73: Add linux riscv64 target
- #66: Fix invalid download crash install
- #61: download.js fails to handle invalid downloads
-
1.15.13 - 2025-06-10
- #72: 1.15.13
- #71: Bump prebuilt to v13.0.0-13
- #70: chore: modernize the pipeline
- #69: 1.15.12
-
1.15.11 - 2025-03-08
- #67: Retry when download fails
-
1.15.10 - 2025-01-10
-
1.15.9 - 2023-11-21
from @vscode/ripgrep GitHub release notesChanges:
This list of changes was auto generated.
Changes:
This list of changes was auto generated.
Changes:
This list of changes was auto generated.
Changes:
This list of changes was auto generated.
No content.
bump to 1.15.9
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
Summary by cubic
Upgrade @vscode/ripgrep from 1.15.9 to 1.17.0 to keep the search binary current and address Snyk recommendations. Updated package-lock.json; package.json no longer includes @vscode/ripgrep and adds a second axios entry—no runtime code changes.
Written for commit 5d37729. Summary will update automatically on new commits.