diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..3618604 --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - async > lodash: + patched: '2023-03-12T07:56:58.961Z' diff --git a/package-lock.json b/package-lock.json index c713c73..f7e7add 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,9 +1,14 @@ { "name": "sharelock", - "version": "0.1.0-pre", + "version": "0.1.1-pre", "lockfileVersion": 1, "requires": true, "dependencies": { + "@snyk/protect": { + "version": "1.1117.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.1117.0.tgz", + "integrity": "sha512-bLmwgrNlF7ffuOWom1lB4yesHqM3wOL7/SnGkMrCm/KBzCx12Lq3WQ6ZwpmNZXNjX9wTm8dgX79YYJBNnVmJLw==" + }, "accepts": { "version": "1.3.4", "resolved": "https://registry.npmjs.org/accepts/-/accepts-1.3.4.tgz", @@ -735,6 +740,7 @@ "version": "1.4.0", "resolved": "https://registry.npmjs.org/once/-/once-1.4.0.tgz", "integrity": "sha1-WDsap3WWHUsROsF9nFC6753Xa9E=", + "optional": true, "requires": { "wrappy": "1.0.2" } @@ -1139,7 +1145,8 @@ "wrappy": { "version": "1.0.2", "resolved": "https://registry.npmjs.org/wrappy/-/wrappy-1.0.2.tgz", - "integrity": "sha1-tSQ9jz7BqjXxNkYFvA0QNuMKtp8=" + "integrity": "sha1-tSQ9jz7BqjXxNkYFvA0QNuMKtp8=", + "optional": true }, "xtend": { "version": "4.0.1", diff --git a/package.json b/package.json index eebb584..cdf73aa 100644 --- a/package.json +++ b/package.json @@ -8,7 +8,9 @@ "version": "0.1.1-pre", "description": "Securely share data", "scripts": { - "start": "node server.js" + "start": "node server.js", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "tags": [ "nodejs", @@ -42,7 +44,8 @@ "passport": "^0.4.0", "passport-auth0": "^0.6.1", "serve-favicon": "^2.4.5", - "swig": "^1.4.2" + "swig": "^1.4.2", + "@snyk/protect": "latest" }, "homepage": "http://github.com/auth0/sharelock", "repository": { @@ -51,5 +54,6 @@ }, "bugs": { "url": "http://github.com/auth0/sharelock/issues" - } + }, + "snyk": true } \ No newline at end of file