From 2ab260d70e8ee68fab30aaa5de3ce805a3048b3c Mon Sep 17 00:00:00 2001 From: snyk-test Date: Tue, 9 Jul 2019 03:02:55 +0000 Subject: [PATCH] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 --- .snyk | 27 ++++++++++++++++++++++++++- package.json | 2 +- 2 files changed, 27 insertions(+), 2 deletions(-) diff --git a/.snyk b/.snyk index eb9f8f8..38fb490 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.12.0 +version: v1.13.5 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -12,3 +12,28 @@ patch: 'npm:tunnel-agent:20170305': - unirest > request > tunnel-agent: patched: '2018-06-26T01:48:38.962Z' + SNYK-JS-LODASH-450202: + - snyk > snyk-nuget-plugin > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > inquirer > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-config > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2019-07-09T03:02:53.871Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2019-07-09T03:02:53.871Z' + - unirest > request > form-data > async > lodash: + patched: '2019-07-09T03:02:53.871Z' diff --git a/package.json b/package.json index e13e3b5..f9763ce 100644 --- a/package.json +++ b/package.json @@ -52,7 +52,7 @@ "unirest": "^0.5.1", "userhome": "^1.0.0", "when": "^3.7.8", - "snyk": "^1.85.0" + "snyk": "^1.192.4" }, "devDependencies": { "babel-preset-es2015": "^6.24.0",