diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..f45297e --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.22.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - request-promise > request-promise-core > lodash: + patched: '2022-03-30T16:04:22.771Z' diff --git a/package-lock.json b/package-lock.json index e4daaea..f49d5f2 100644 --- a/package-lock.json +++ b/package-lock.json @@ -121,6 +121,11 @@ "integrity": "sha512-aalIRUtcR6nPf50kEwnYvepSJIdpulrbMeeNMwiOmFgBg4MgScCmlI7SqOmsGJNqaH65+benoqt0H4N0RR2Okg==", "dev": true }, + "@snyk/protect": { + "version": "1.890.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.890.0.tgz", + "integrity": "sha512-xloJx6b1OROkP0wk+lQgc3nMNaR0QdxokqxwErIK0rBFT+FVNrXCySXOWUzr8mUHqvJBYa5/7o71h2mCAiAvCQ==" + }, "@types/json5": { "version": "0.0.29", "resolved": "https://registry.npmjs.org/@types/json5/-/json5-0.0.29.tgz", diff --git a/package.json b/package.json index c724d3f..1478584 100644 --- a/package.json +++ b/package.json @@ -10,7 +10,9 @@ "test": "istanbul cover _mocha", "release:major": "changelog -M && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version major && git push origin && git push origin --tags && npm publish", "release:minor": "changelog -m && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version minor && git push origin && git push origin --tags && npm publish", - "release:patch": "changelog -p && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version patch && git push origin && git push origin --tags && npm publish" + "release:patch": "changelog -p && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version patch && git push origin && git push origin --tags && npm publish", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "engines": { "node": ">=6" @@ -32,7 +34,8 @@ "homepage": "https://github.com/lgaticaq/m2m-status#readme", "dependencies": { "request": "2.88.2", - "request-promise": "4.2.6" + "request-promise": "4.2.6", + "@snyk/protect": "latest" }, "devDependencies": { "chai": "4.3.4", @@ -69,5 +72,6 @@ "extends": [ ":library" ] - } + }, + "snyk": true }