From 09d4504f9b627f2bb688854537a4d2ef752735d2 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 6 May 2020 04:57:57 +0530 Subject: [PATCH 1/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- package.json | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/package.json b/package.json index 689510d..ac85c2c 100644 --- a/package.json +++ b/package.json @@ -9,7 +9,9 @@ "main": "index.js", "scripts": { "test": "mocha test/** --recursive", - "build-deb": "./scripts/build-deb" + "build-deb": "./scripts/build-deb", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "bin": { "flashcore": "./bin/flashcore", @@ -96,6 +98,8 @@ "flashcore-lib": "flash-coin/flashcore-lib", "flashcore-node": "flash-coin/flashcore-node", "insight-flash-api": "flash-coin/insight-flash-api", - "insight-flash-ui": "flash-coin/insight-flash-ui" - } + "insight-flash-ui": "flash-coin/insight-flash-ui", + "snyk": "^1.319.0" + }, + "snyk": true } From cfaec0498add3d9abe78f78401202e9f0985a6d8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 6 May 2020 04:57:57 +0530 Subject: [PATCH 2/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..ee69558 --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - insight-flash-api > lodash: + patched: '2020-05-05T23:27:53.139Z'