diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..ed18c88 --- /dev/null +++ b/.snyk @@ -0,0 +1,24 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.22.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - pkgcloud > lodash: + patched: '2022-03-26T16:26:51.944Z' + - dynamodb-x > lodash: + patched: '2022-03-26T16:26:51.944Z' + - pkgcloud > async > lodash: + patched: '2022-03-26T16:26:51.944Z' + - winston > async > lodash: + patched: '2022-03-26T16:26:51.944Z' + - pkgcloud > @google-cloud/storage > async > lodash: + patched: '2022-03-26T16:26:51.944Z' + - workers-factory > minimize > async > lodash: + patched: '2022-03-26T16:26:51.944Z' + - bffs > cdnup > pkgcloud > lodash: + patched: '2022-03-26T16:26:51.944Z' + - bffs > cdnup > pkgcloud > async > lodash: + patched: '2022-03-26T16:26:51.944Z' + - bffs > cdnup > pkgcloud > @google-cloud/storage > async > lodash: + patched: '2022-03-26T16:26:51.944Z' diff --git a/package-lock.json b/package-lock.json index 406d3df..ad9fceb 100644 --- a/package-lock.json +++ b/package-lock.json @@ -235,6 +235,11 @@ "integrity": "sha512-+iTbntw2IZPb/anVDbypzfQa+ay64MW0Zo8aJ8gZPWMMK6/OubMVb6lUPMagqjOPnmtauXnFCACVl3O7ogjeqQ==", "dev": true }, + "@snyk/protect": { + "version": "1.883.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.883.0.tgz", + "integrity": "sha512-N/EqG6P/qNYWOfuZAfGS1d7yGwGY4zV7AvKtgTzdhazDt7G/mRLG6czLSWNWGEFYBiMsYRVPHdc5It3bjhmIGw==" + }, "@types/caseless": { "version": "0.12.2", "resolved": "https://registry.npmjs.org/@types/caseless/-/caseless-0.12.2.tgz", diff --git a/package.json b/package.json index d89c0f1..16bcde3 100644 --- a/package.json +++ b/package.json @@ -8,7 +8,9 @@ "lint:fix": "eslint-godaddy --fix preboot/ test/ *.js", "lint": "eslint-godaddy preboot/ test/ *.js", "posttest": "npm run lint:fix", - "test": "nyc mocha" + "test": "nyc mocha", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "repository": { "type": "git", @@ -45,7 +47,8 @@ "uuid": "^3.3.3", "warehouse-models": "^6.0.0", "winston": "^3.2.1", - "workers-factory": "^3.1.0" + "workers-factory": "^3.1.0", + "@snyk/protect": "latest" }, "devDependencies": { "assume": "^2.2.0", @@ -58,5 +61,6 @@ "mocha": "^6.1.4", "nyc": "^14.1.1", "sinon": "^7.3.2" - } + }, + "snyk": true }