From 00abe03180af7c4ad7dc2830576895a8f5ec8b33 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Tue, 26 Feb 2019 02:59:28 +0000 Subject: [PATCH] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:hawk:20160119 - https://snyk.io/vuln/npm:http-signature:20150122 - https://snyk.io/vuln/npm:mime:20170907 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:request:20160119 - https://snyk.io/vuln/npm:tunnel-agent:20170305 - https://snyk.io/vuln/npm:uglify-js:20151024 --- .snyk | 42 ++++++++++++++++++++++++++++++++++++++++++ package.json | 10 +++++++--- 2 files changed, 49 insertions(+), 3 deletions(-) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..e5eff61 --- /dev/null +++ b/.snyk @@ -0,0 +1,42 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.3 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:hawk:20160119': + - highlight.js > gear-lib > less > request > hawk: + patched: '2019-02-26T02:59:26.359Z' + 'npm:http-signature:20150122': + - highlight.js > gear-lib > less > request > http-signature: + patched: '2019-02-26T02:59:26.359Z' + 'npm:mime:20170907': + - highlight.js > gear-lib > mime: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > less > mime: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > less > request > form-data > mime: + patched: '2019-02-26T02:59:26.359Z' + 'npm:minimatch:20160620': + - highlight.js > gear > liftoff > findup-sync > glob > minimatch: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > gear > liftoff > findup-sync > glob > minimatch: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > glob > minimatch: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > jslint > glob > minimatch: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > jshint > cli > glob > minimatch: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > jshint > minimatch: + patched: '2019-02-26T02:59:26.359Z' + 'npm:request:20160119': + - highlight.js > gear-lib > less > request: + patched: '2019-02-26T02:59:26.359Z' + 'npm:tunnel-agent:20170305': + - highlight.js > gear-lib > less > request > tunnel-agent: + patched: '2019-02-26T02:59:26.359Z' + 'npm:uglify-js:20151024': + - highlight.js > gear-lib > handlebars > uglify-js: + patched: '2019-02-26T02:59:26.359Z' + - highlight.js > gear-lib > uglify-js: + patched: '2019-02-26T02:59:26.359Z' diff --git a/package.json b/package.json index c8fd316..6d75f95 100644 --- a/package.json +++ b/package.json @@ -30,7 +30,9 @@ "watch": "gulp watch", "gulp": "gulp", "modclean": "modclean -r -n safe, caution, danger", - "test": "xo ./src/**/*.js !./src/public/assets/js/*.*" + "test": "xo ./src/**/*.js !./src/public/assets/js/*.*", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "dependencies": { "@lasso/marko-taglib": "^1.0.10", @@ -67,7 +69,8 @@ "shortid": "^2.2.8", "source-map-support": "^0.5.0", "uglify-es": "^3.3.2", - "winston": "^3.0.0" + "winston": "^3.0.0", + "snyk": "^1.134.2" }, "devDependencies": { "babel-cli": "^6.26.0", @@ -170,5 +173,6 @@ "coveragePathIgnorePatterns": [ "/node_modules" ] - } + }, + "snyk": true }