From 8f5772bba2e8cc1e6ab81ea3076c20de74b84113 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 17 Jan 2022 14:01:54 +0000 Subject: [PATCH] fix: tools/remark-cli/package.json, tools/remark-cli/package-lock.json & tools/remark-cli/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:extend:20180424 --- tools/remark-cli/.snyk | 8 ++++++++ tools/remark-cli/package-lock.json | 6 +++++- tools/remark-cli/package.json | 11 ++++++++--- 3 files changed, 21 insertions(+), 4 deletions(-) create mode 100644 tools/remark-cli/.snyk diff --git a/tools/remark-cli/.snyk b/tools/remark-cli/.snyk new file mode 100644 index 00000000000000..71d11c7056ce25 --- /dev/null +++ b/tools/remark-cli/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.22.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:extend:20180424': + - remark > unified > extend: + patched: '2022-01-17T14:01:21.419Z' diff --git a/tools/remark-cli/package-lock.json b/tools/remark-cli/package-lock.json index e47a22823d9e8f..d65d6bd5f7c79e 100644 --- a/tools/remark-cli/package-lock.json +++ b/tools/remark-cli/package-lock.json @@ -2,9 +2,13 @@ "name": "remark-cli", "version": "4.0.0", "lockfileVersion": 1, - "preserveSymlinks": "1", "requires": true, "dependencies": { + "@snyk/protect": { + "version": "1.831.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.831.0.tgz", + "integrity": "sha512-za7rvnHvnjGQwd60fYu3NopU9SCelSKrAUJNA4nVUgjdbkn+HA+cfvYo5DeU6QI5RpzTNCWJdJ26FkxXFEJ3bQ==" + }, "ansi-regex": { "version": "2.1.1", "resolved": "https://registry.npmjs.org/ansi-regex/-/ansi-regex-2.1.1.tgz", diff --git a/tools/remark-cli/package.json b/tools/remark-cli/package.json index 52a906e5ba224d..1a5aea04dedec0 100644 --- a/tools/remark-cli/package.json +++ b/tools/remark-cli/package.json @@ -12,7 +12,8 @@ "dependencies": { "markdown-extensions": "^1.1.0", "remark": "^8.0.0", - "unified-args": "^4.0.0" + "unified-args": "^4.0.0", + "@snyk/protect": "latest" }, "homepage": "http://remark.js.org", "repository": "https://github.com/wooorm/remark/tree/master/packages/remark-cli", @@ -27,6 +28,10 @@ "files": [ "cli.js" ], - "scripts": {}, - "xo": false + "scripts": { + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" + }, + "xo": false, + "snyk": true }