From b945eae398a18d0c99e0b6a512e6499bfc2ef77c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 04:12:50 +0700 Subject: [PATCH 1/2] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..9da58e4 --- /dev/null +++ b/.snyk @@ -0,0 +1,32 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - snyk > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > inquirer > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-config > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-nuget-plugin > lodash: + patched: '2020-04-30T21:12:49.017Z' + - winston > async > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-nuget-plugin > dotnet-deps-parser > lodash: + patched: '2020-04-30T21:12:49.017Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2020-04-30T21:12:49.017Z' From d1effeb3ad4d98b04cdb36c41cae9e730bf72840 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 04:12:51 +0700 Subject: [PATCH 2/2] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- package.json | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 4045641..27d138f 100644 --- a/package.json +++ b/package.json @@ -24,7 +24,7 @@ "plur": "^3.1.1", "ramda": "^0.26.1", "request": "^2.88.0", - "snyk": "^1.221.1", + "snyk": "^1.316.1", "winston": "^3.2.1", "yn": "^3.1.1" }, @@ -68,7 +68,8 @@ "vulnerabilities": "yarn snyk test", "test": "yarn seed -d && npx jest --detectOpenHandles --forceExit --coverage", "test-with-coverage": "yarn test && cat ./coverage/lcov.info | codacy-coverage", - "snyk-protect": "snyk protect" + "snyk-protect": "snyk protect", + "prepare": "yarn run snyk-protect" }, "snyk": true }