fix: package.json & .snyk to reduce vulnerabilities

The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/npm:debug:20170905

Latest report for samsonjs/samhuri.net:
https://snyk.io/test/github/samsonjs/samhuri.net
This commit is contained in:
snyk-bot 2017-09-29 03:22:09 +00:00
parent 34cbede753
commit 2718ac19a0
2 changed files with 25 additions and 3 deletions

23
.snyk
View file

@ -1,5 +1,5 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.7.0
version: v1.7.1
ignore: {}
# patches apply the minimum changes required to fix a vulnerability
patch:
@ -20,3 +20,24 @@ patch:
'npm:uglify-js:20151024':
- harp > terraform > jade > transformers > uglify-js:
patched: '2017-04-21T04:58:35.183Z'
'npm:debug:20170905':
- harp > connect > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > express-session > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > finalhandler > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > morgan > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-index > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > send > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > body-parser > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > compression > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > connect-timeout > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-static > send > debug:
patched: '2017-09-29T03:22:08.982Z'

View file

@ -6,11 +6,12 @@
"harp": "^0.24.0",
"thepusher": "^0.1.4",
"uglify-js": "^3.0.9",
"snyk": "^1.30.1"
"snyk": "^1.41.1"
},
"scripts": {
"snyk-protect": "snyk protect",
"prepublish": "npm run snyk-protect"
"prepublish": "npm run snyk-protect",
"prepare": "npm run snyk-protect"
},
"snyk": true
}