From d942dd5b5d0dcb1336dec0124013826eedc03b2d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 4 Jun 2020 02:33:21 +0000 Subject: [PATCH] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 8 ++++++++ package.json | 9 ++++++--- 2 files changed, 14 insertions(+), 3 deletions(-) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..41289e6 --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - schema-inspector > async > lodash: + patched: '2020-06-04T02:33:19.445Z' diff --git a/package.json b/package.json index ee02943..9d68d2b 100644 --- a/package.json +++ b/package.json @@ -6,7 +6,8 @@ "scripts": { "test": "jest", "build": "webpack", - "prepublish": "npm run build" + "prepublish": "npm run snyk-protect && npm run build", + "snyk-protect": "snyk protect" }, "repository": "dstreet/polymod", "author": "David Street", @@ -17,7 +18,8 @@ "schema-inspector": "^1.6.8", "sift": "^3.2.7", "uuid": "^3.0.1", - "uuid-validate": "0.0.2" + "uuid-validate": "0.0.2", + "snyk": "^1.335.0" }, "devDependencies": { "babel-core": "^6.23.1", @@ -30,5 +32,6 @@ "eslint": "^4.1.1", "jest": "^20.0.4", "webpack": "^2.2.1" - } + }, + "snyk": true }