diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..65c26d6 --- /dev/null +++ b/.snyk @@ -0,0 +1,22 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - lodash: + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > @frctl/mandelbrot > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > inquirer > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > vorpal > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > browser-sync > easy-extender > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > sinon > build > winston > async > lodash': + patched: '2020-05-01T08:01:51.605Z' + - '@frctl/fractal > sinon > nise > @sinonjs/formatio > @sinonjs/samsam > lodash': + patched: '2020-05-01T08:01:51.605Z' diff --git a/package.json b/package.json index 11cb411..4aba0ee 100644 --- a/package.json +++ b/package.json @@ -22,16 +22,20 @@ "drupal-attribute": "1.0.2", "lodash": "^4.17.4", "query-string": "^5.0.0", - "twig": "1.10.5" + "twig": "1.10.5", + "snyk": "^1.316.1" }, "scripts": { "release:major": "npm version major -m \"Released version %s\" && npm publish && git push --follow-tags", "release:minor": "npm version minor -m \"Released version %s\" && npm publish && git push --follow-tags", - "release:patch": "npm version patch -m \"Released version %s\" && npm publish && git push --follow-tags" + "release:patch": "npm version patch -m \"Released version %s\" && npm publish && git push --follow-tags", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "babel": { "presets": [ "es2015" ] - } + }, + "snyk": true }