Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
9712bee
Add .whitesource configuration file
mend-bolt-for-github[bot] Sep 16, 2020
8c27b25
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Nov 25, 2020
957e7b8
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Nov 25, 2020
139fed4
fix: upgrade marked from 0.3.6 to 0.8.2
snyk-bot Nov 25, 2020
12554b6
fix: upgrade commander from 2.11.0 to 2.20.3
snyk-bot Nov 25, 2020
9abe680
fix: upgrade lodash from 4.17.4 to 4.17.20
snyk-bot Nov 25, 2020
9298863
fix: upgrade js-yaml from 3.9.0 to 3.14.0
snyk-bot Nov 25, 2020
085736c
Merge pull request #9 from cniweb/snyk-upgrade-d8f563f0d25eda210c2306…
cniweb Dec 8, 2020
66fb546
Merge pull request #1 from cniweb/whitesource/configure
cniweb Dec 8, 2020
8f11866
Merge pull request #2 from cniweb/snyk-fix-01e97b29a8c036703273346a2d…
cniweb Dec 8, 2020
dc1d06b
Merge pull request #3 from cniweb/snyk-fix-d85ac0720f76d4cf096166e7bf…
cniweb Dec 8, 2020
9892d27
Merge pull request #5 from cniweb/snyk-upgrade-fb1faf5fec4152a4f5b5a2…
cniweb Dec 8, 2020
d55da06
Merge pull request #6 from cniweb/snyk-upgrade-a8370225782301fa5fc4f1…
cniweb Dec 8, 2020
0a48331
Merge pull request #7 from cniweb/snyk-upgrade-89112774acaad2d1dba322…
cniweb Dec 8, 2020
064faa2
fix: package.json, yarn.lock & .snyk to reduce vulnerabilities
snyk-bot Dec 8, 2020
741bfc7
Merge pull request #10 from cniweb/snyk-fix-f1bd2fa3941665eca83a01f9e…
cniweb Dec 8, 2020
995da7f
fix: upgrade semver from 5.3.0 to 5.7.1
snyk-bot Dec 9, 2020
b947a37
fix: upgrade http-errors from 1.6.1 to 1.8.0
snyk-bot Dec 9, 2020
4a1d1bf
fix: upgrade marked from 1.1.1 to 1.2.4
snyk-bot Dec 9, 2020
16dd8d1
fix: upgrade express from 4.16.0 to 4.17.1
snyk-bot Dec 9, 2020
1d3348e
Merge pull request #11 from cniweb/snyk-upgrade-b16af2d13c7934f4be50e…
cniweb Dec 9, 2020
0022372
Merge pull request #12 from cniweb/snyk-upgrade-c69cfeb6479a2a746c008…
cniweb Dec 9, 2020
ecab8d4
Merge pull request #13 from cniweb/snyk-upgrade-574c5ebc88d75896b6c78…
cniweb Dec 9, 2020
12f62e3
Merge pull request #14 from cniweb/snyk-upgrade-355bc77545fae79cfd18c…
cniweb Dec 9, 2020
a86dee0
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Dec 5, 2022
e72bf4a
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Dec 23, 2022
16c4e90
Merge pull request #40 from cniweb/snyk-fix-467aaad1e537b9855110daa45…
cniweb Dec 29, 2022
f383427
Merge pull request #39 from cniweb/snyk-fix-ae253e84a9ab7df782c2fe5cd…
cniweb Dec 29, 2022
aef5cf7
fix: package.json & yarn.lock to reduce vulnerabilities
snyk-bot Nov 30, 2023
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 25 additions & 0 deletions .snyk
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.19.0
ignore: {}
# patches apply the minimum changes required to fix a vulnerability
patch:
'npm:debug:20170905':
- express > finalhandler > debug:
patched: '2020-12-08T21:24:47.536Z'
'npm:extend:20180424':
- request > extend:
patched: '2020-12-08T21:24:47.536Z'
SNYK-JS-LODASH-567746:
- async > lodash:
patched: '2020-12-08T21:24:47.536Z'
'npm:moment:20170905':
- bunyan > moment:
patched: '2020-12-08T21:24:47.536Z'
- jsonwebtoken > joi > moment:
patched: '2020-12-08T21:24:47.536Z'
'npm:stringstream:20180511':
- request > stringstream:
patched: '2020-12-08T21:24:47.536Z'
'npm:tough-cookie:20170905':
- request > tough-cookie:
patched: '2020-12-08T21:24:47.536Z'
12 changes: 12 additions & 0 deletions .whitesource
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{
"scanSettings": {
"baseBranches": []
},
"checkRunSettings": {
"vulnerableCheckRunConclusionLevel": "failure",
"displayMode": "diff"
},
"issueSettings": {
"minSeverityLevel": "LOW"
}
}
43 changes: 23 additions & 20 deletions package.json
Original file line number Diff line number Diff line change
Expand Up @@ -15,35 +15,36 @@
"verdaccio": "./bin/verdaccio"
},
"dependencies": {
"@verdaccio/file-locking": "^0.0.3",
"@verdaccio/file-locking": "^1.0.0",
"JSONStream": "^1.1.1",
"apache-md5": "^1.1.2",
"async": "^2.0.1",
"body-parser": "^1.15.0",
"bunyan": "^1.8.0",
"body-parser": "^1.19.2",
"bunyan": "^1.8.13",
"chalk": "^2.0.1",
"commander": "^2.11.0",
"compression": "1.6.2",
"commander": "^2.20.3",
"compression": "1.7.1",
"cookies": "^0.7.0",
"cors": "^2.8.3",
"express": "4.15.3",
"express": "4.17.3",
"global": "^4.3.2",
"handlebars": "4.0.5",
"http-errors": "^1.4.0",
"handlebars": "4.6.0",
"http-errors": "^1.8.0",
"js-string-escape": "1.0.1",
"js-yaml": "^3.6.0",
"jsonwebtoken": "^7.4.1",
"js-yaml": "^3.14.0",
"jsonwebtoken": "^9.0.0",
"lockfile": "^1.0.1",
"lodash": "4.17.4",
"lodash": "4.17.20",
"lunr": "^0.7.0",
"marked": "0.3.6",
"mime": "^1.3.6",
"marked": "1.2.4",
"mime": "^1.4.1",
"minimatch": "^3.0.2",
"mkdirp": "^0.5.1",
"mkdirp": "^0.5.2",
"pkginfo": "^0.4.0",
"request": "^2.72.0",
"semver": "^5.1.0",
"unix-crypt-td-js": "^1.0.0"
"request": "^2.88.0",
"semver": "^5.7.1",
"unix-crypt-td-js": "^1.0.0",
"snyk": "^1.685.0"
},
"devDependencies": {
"axios": "0.16.2",
Expand Down Expand Up @@ -116,7 +117,7 @@
"server"
],
"scripts": {
"prepublish": "in-publish && npm run build:webui || not-in-publish",
"prepublish": "yarn run snyk-protect && in-publish && npm run build:webui || not-in-publish",
"test": "mocha ./test/functional ./test/unit --reporter=spec --full-trace",
"pre:ci": "npm run build:webui",
"test:ci": "npm run test:coverage",
Expand All @@ -130,7 +131,8 @@
"dev:webui": "babel-node tools/dev.server.js",
"build:webui": "npm run pre:webpack && webpack --config tools/webpack.prod.config.babel.js",
"build:docker": "docker build -t verdaccio . --no-cache",
"build:docker:rpi": "docker build -f Dockerfile.rpi -t verdaccio:rpi ."
"build:docker:rpi": "docker build -f Dockerfile.rpi -t verdaccio:rpi .",
"snyk-protect": "snyk protect"
},
"jest": {
"snapshotSerializers": [
Expand All @@ -145,5 +147,6 @@
"publishConfig": {
"registry": "https://registry.npmjs.org/"
},
"license": "WTFPL"
"license": "WTFPL",
"snyk": true
}
Loading