fix: package.json & .snyk to reduce vulnerabilities

The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/npm:debug:20170905

Latest report for samsonjs/samhuri.net:
https://snyk.io/test/github/samsonjs/samhuri.net
This commit is contained in:
snyk-bot 2017-09-29 03:22:09 +00:00
parent 34cbede753
commit 2718ac19a0
2 changed files with 25 additions and 3 deletions

23
.snyk
View file

@ -1,5 +1,5 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.7.0 version: v1.7.1
ignore: {} ignore: {}
# patches apply the minimum changes required to fix a vulnerability # patches apply the minimum changes required to fix a vulnerability
patch: patch:
@ -20,3 +20,24 @@ patch:
'npm:uglify-js:20151024': 'npm:uglify-js:20151024':
- harp > terraform > jade > transformers > uglify-js: - harp > terraform > jade > transformers > uglify-js:
patched: '2017-04-21T04:58:35.183Z' patched: '2017-04-21T04:58:35.183Z'
'npm:debug:20170905':
- harp > connect > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > express-session > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > finalhandler > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > morgan > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-index > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > send > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > body-parser > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > compression > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > connect-timeout > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-static > send > debug:
patched: '2017-09-29T03:22:08.982Z'

View file

@ -6,11 +6,12 @@
"harp": "^0.24.0", "harp": "^0.24.0",
"thepusher": "^0.1.4", "thepusher": "^0.1.4",
"uglify-js": "^3.0.9", "uglify-js": "^3.0.9",
"snyk": "^1.30.1" "snyk": "^1.41.1"
}, },
"scripts": { "scripts": {
"snyk-protect": "snyk protect", "snyk-protect": "snyk protect",
"prepublish": "npm run snyk-protect" "prepublish": "npm run snyk-protect",
"prepare": "npm run snyk-protect"
}, },
"snyk": true "snyk": true
} }