From a2e0be343460564d0940fca3f57ea656243bb38d Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 30 Jul 2021 20:22:03 +0000 Subject: [PATCH] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:hoek:20180212 - https://snyk.io/vuln/npm:request:20160119 - https://snyk.io/vuln/npm:tough-cookie:20170905 - https://snyk.io/vuln/npm:tunnel-agent:20170305 --- .snyk | 33 +++++++++++++++++++++++++++++++++ package.json | 10 +++++++--- 2 files changed, 40 insertions(+), 3 deletions(-) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..f770532 --- /dev/null +++ b/.snyk @@ -0,0 +1,33 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.21.5 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:hoek:20180212': + - node-cloud-vision-api > googleapis > request > hawk > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > request > hawk > boom > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > request > hawk > sntp > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > google-auth-library > request > hawk > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > request > hawk > cryptiles > boom > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > google-auth-library > request > hawk > boom > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > google-auth-library > request > hawk > sntp > hoek: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > google-auth-library > request > hawk > cryptiles > boom > hoek: + patched: '2021-07-30T20:22:02.136Z' + 'npm:request:20160119': + - node-cloud-vision-api > googleapis > request: + patched: '2021-07-30T20:22:02.136Z' + 'npm:tough-cookie:20170905': + - node-cloud-vision-api > googleapis > request > tough-cookie: + patched: '2021-07-30T20:22:02.136Z' + 'npm:tunnel-agent:20170305': + - node-cloud-vision-api > googleapis > request > tunnel-agent: + patched: '2021-07-30T20:22:02.136Z' + - node-cloud-vision-api > googleapis > google-auth-library > request > tunnel-agent: + patched: '2021-07-30T20:22:02.136Z' diff --git a/package.json b/package.json index c6da8ec..493b2dc 100644 --- a/package.json +++ b/package.json @@ -3,7 +3,9 @@ "version": "0.0.0", "private": true, "scripts": { - "start": "nodemon -e .ejs,.js,.css ./bin/www" + "start": "nodemon -e .ejs,.js,.css ./bin/www", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "dependencies": { "async": "^2.3.0", @@ -20,9 +22,11 @@ "morgan": "~1.8.1", "node-cloud-vision-api": "^0.2.0", "request": "^2.81.0", - "serve-favicon": "~2.4.2" + "serve-favicon": "~2.4.2", + "@snyk/protect": "latest" }, "devDependencies": { "nodemon": "^1.11.0" - } + }, + "snyk": true }