From e95f209b1ee74552fa0c2b5c24527e25fb44b069 Mon Sep 17 00:00:00 2001 From: snyk-test Date: Thu, 4 Jul 2019 21:53:48 +0000 Subject: [PATCH] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 --- .snyk | 39 ++++++++++++++++++++++++++++++++++++++- package.json | 5 +++-- 2 files changed, 41 insertions(+), 3 deletions(-) diff --git a/.snyk b/.snyk index 0a74b6e..b6fe7d6 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.12.0 +version: v1.13.5 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -20,3 +20,40 @@ patch: patched: '2018-06-21T06:49:26.836Z' - botbuilder-location > botbuilder > jsonwebtoken > joi > topo > hoek: patched: '2018-06-21T06:49:26.836Z' + SNYK-JS-LODASH-450202: + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > lodash: + patched: '2019-07-04T21:53:46.422Z' + - restify > lodash: + patched: '2019-07-04T21:53:46.422Z' + - botbuilder-cognitiveservices > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-nuget-plugin > lodash: + patched: '2019-07-04T21:53:46.422Z' + - restify > restify-errors > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > inquirer > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-config > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2019-07-04T21:53:46.422Z' + - dotenv-extended > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2019-07-04T21:53:46.422Z' + - botbuilder > botframework-connector > nock > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2019-07-04T21:53:46.422Z' + - botbuilder-location > request-promise > request-promise-core > lodash: + patched: '2019-07-04T21:53:46.422Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2019-07-04T21:53:46.422Z' + - botbuilder-azure > botbuilder > botframework-connector > nock > lodash: + patched: '2019-07-04T21:53:46.422Z' diff --git a/package.json b/package.json index e0dc1e6..1e880b2 100644 --- a/package.json +++ b/package.json @@ -11,7 +11,7 @@ "dotenv-extended": "^2.0.1", "restify": "^5.0.0", "schema-inspector": "^1.6.8", - "snyk": "^1.83.0" + "snyk": "^1.192.0" }, "devDependencies": { "request": "^2.81.0", @@ -20,7 +20,8 @@ "scripts": { "test": "echo \"Error: no test specified\" && exit 1", "snyk-protect": "snyk protect", - "prepare": "npm run snyk-protect" + "prepare": "npm run snyk-protect", + "prepublish": "npm run snyk-protect" }, "author": "", "license": "ISC",