diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..a26f2d5 --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.22.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - tc-core-library-js > lodash: + patched: '2022-03-26T02:37:29.368Z' diff --git a/package-lock.json b/package-lock.json index 1226c91..571eaac 100644 --- a/package-lock.json +++ b/package-lock.json @@ -213,6 +213,11 @@ "integrity": "sha512-+iTbntw2IZPb/anVDbypzfQa+ay64MW0Zo8aJ8gZPWMMK6/OubMVb6lUPMagqjOPnmtauXnFCACVl3O7ogjeqQ==", "dev": true }, + "@snyk/protect": { + "version": "1.883.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.883.0.tgz", + "integrity": "sha512-N/EqG6P/qNYWOfuZAfGS1d7yGwGY4zV7AvKtgTzdhazDt7G/mRLG6czLSWNWGEFYBiMsYRVPHdc5It3bjhmIGw==" + }, "@types/bluebird": { "version": "3.5.0", "resolved": "https://registry.npmjs.org/@types/bluebird/-/bluebird-3.5.0.tgz", @@ -2913,9 +2918,9 @@ } }, "lodash": { - "version": "4.17.19", - "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.19.tgz", - "integrity": "sha512-JNvd8XER9GQX0v2qJgsaN/mzFCNA5BRe/j8JN9d+tWyGLSodKQHKFicdwNYzWwI3wjRnaKPsGj1XkBjx/F96DQ==" + "version": "4.17.20", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.20.tgz", + "integrity": "sha512-PlhdFcillOINfeV7Ni6oF1TAEayyZBoZ8bcshTHqOYJYlrqzRK5hagpagky5o4HfCzzd1TRkXPMFq6cKk9rGmA==" }, "lodash.clonedeep": { "version": "4.5.0", diff --git a/package.json b/package.json index e35a1a9..4c041d0 100644 --- a/package.json +++ b/package.json @@ -13,7 +13,9 @@ "helper:test": "nyc --silent mocha test/helper.test.js --exit", "processor:test": "nyc --silent --no-clean mocha --require test/prepare.js test/processor.test.js --timeout 20000 --exit", "cover:report": "nyc report --reporter=html --reporter=text", - "test:cov": "npm run helper:test && npm run processor:test && npm run cover:report" + "test:cov": "npm run helper:test && npm run processor:test && npm run cover:report", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "author": "TCSCODER", "license": "none", @@ -35,11 +37,12 @@ "get-parameter-names": "^0.3.0", "html-entities": "^1.2.1", "ifxnjs": "^8.0.1", - "lodash": "^4.17.19", + "lodash": "^4.17.20", "no-kafka": "^3.4.3", "tc-core-library-js": "github:appirio-tech/tc-core-library-js#v2.6.3", "topcoder-healthcheck-dropin": "^1.0.3", - "winston": "^3.2.1" + "winston": "^3.2.1", + "@snyk/protect": "latest" }, "engines": { "node": "8.x" @@ -54,5 +57,6 @@ "scripts/*.js", "test/*.js" ] - } + }, + "snyk": true }