Merge pull request #21 from samsonjs/snyk-fix-3d73353f

[Snyk Update] New fixes for 10 vulnerable dependency paths
This commit is contained in:
Sami Samhuri 2019-11-15 10:44:01 -08:00 committed by GitHub
commit 7f3947009a
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 30 additions and 3 deletions

23
.snyk
View file

@ -1,5 +1,5 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.7.0
version: v1.7.1
ignore: {}
# patches apply the minimum changes required to fix a vulnerability
patch:
@ -20,3 +20,24 @@ patch:
'npm:uglify-js:20151024':
- harp > terraform > jade > transformers > uglify-js:
patched: '2017-04-21T04:58:35.183Z'
'npm:debug:20170905':
- harp > connect > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > express-session > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > finalhandler > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > morgan > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-index > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > send > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > body-parser > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > compression > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > connect-timeout > debug:
patched: '2017-09-29T03:22:08.982Z'
- harp > connect > serve-static > send > debug:
patched: '2017-09-29T03:22:08.982Z'

View file

@ -5,7 +5,13 @@
"dependencies": {
"harp": "^0.29.0",
"thepusher": "^0.1.4",
"uglify-js": "^3.4.9"
"uglify-js": "^3.4.9",
"snyk": "^1.41.1"
},
"scripts": {}
"scripts": {
"snyk-protect": "snyk protect",
"prepublish": "npm run snyk-protect",
"prepare": "npm run snyk-protect"
},
"snyk": true
}