From 3e9d1af6e735c3e0b3aefdc5e094991691eef89b Mon Sep 17 00:00:00 2001 From: snyk-test Date: Tue, 9 Jul 2019 05:48:45 +0000 Subject: [PATCH] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 --- .snyk | 31 ++++++++++++++++++++++++++++++- package.json | 2 +- 2 files changed, 31 insertions(+), 2 deletions(-) diff --git a/.snyk b/.snyk index 556a6458..66945315 100644 --- a/.snyk +++ b/.snyk @@ -1,6 +1,35 @@ -version: v1.5.0 +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.5 ignore: {} +# patches apply the minimum changes required to fix a vulnerability patch: 'npm:request:20160119': - googleapis > google-auth-library > request: patched: '2016-09-20T14:31:33.007Z' + SNYK-JS-LODASH-450202: + - googleapis > async > lodash: + patched: '2019-07-09T05:48:43.236Z' + - fast-csv > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-config > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > inquirer > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-nuget-plugin > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2019-07-09T05:48:43.236Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2019-07-09T05:48:43.236Z' diff --git a/package.json b/package.json index db835c58..d7c283fe 100644 --- a/package.json +++ b/package.json @@ -61,7 +61,7 @@ "lodash": "^3.10.1", "minimist": "*", "node-schedule": "^0.1.13", - "snyk": "^1.19.1" + "snyk": "^1.192.4" }, "devDependencies": { "body-parser": "~1.8.1",