diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..b99f6bf --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - '@typescript-eslint/typescript-estree > lodash': + patched: '2022-10-07T14:21:37.181Z' diff --git a/package-lock.json b/package-lock.json index c4f2d89..8d35bba 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,6 +1,6 @@ { "name": "bit-javascript", - "version": "2.1.6-dev.2", + "version": "2.1.6-dev.3", "lockfileVersion": 1, "requires": true, "dependencies": { @@ -1857,6 +1857,11 @@ "integrity": "sha512-+iTbntw2IZPb/anVDbypzfQa+ay64MW0Zo8aJ8gZPWMMK6/OubMVb6lUPMagqjOPnmtauXnFCACVl3O7ogjeqQ==", "dev": true }, + "@snyk/protect": { + "version": "1.1025.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.1025.0.tgz", + "integrity": "sha512-RK9tY2Aqujv5l9e/5nE4yiTilk8vxyB99VtJJ/6p9TZYhddCVQUUv+PNenhVVO3jkSD8/3gLWbPakIvQsFKynA==" + }, "@types/eslint-visitor-keys": { "version": "1.0.0", "resolved": "https://registry.npmjs.org/@types/eslint-visitor-keys/-/eslint-visitor-keys-1.0.0.tgz", @@ -7049,9 +7054,9 @@ "dev": true }, "ramda": { - "version": "0.26.1", - "resolved": "https://registry.npmjs.org/ramda/-/ramda-0.26.1.tgz", - "integrity": "sha512-hLWjpy7EnsDBb0p+Z3B7rPi3GDeRG5ZtiI33kJhTt+ORCd38AbAIjB/9zRIUoeTbE/AVX5ZkU7m6bznsvrf8eQ==" + "version": "0.27.2", + "resolved": "https://registry.npmjs.org/ramda/-/ramda-0.27.2.tgz", + "integrity": "sha512-SbiLPU40JuJniHexQSAgad32hfwd+DRUdwF2PlVuI5RZD0/vahUco7R8vD86J/tcEKKF9vZrUVwgtmGCqlCKyA==" }, "rc": { "version": "1.2.8", diff --git a/package.json b/package.json index 1a5c3ac..27acfec 100644 --- a/package.json +++ b/package.json @@ -17,7 +17,9 @@ "build-debug": "babel src -d dist --source-maps", "pre-release": "gh-release --prerelease", "release": "gh-release", - "release:circle": "gh-release -y" + "release:circle": "gh-release -y", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "bin": { "bitjs": "bin/bitjs.js" @@ -63,7 +65,7 @@ "object-assign": "^4.1.1", "ora": "^1.2.0", "parents": "^1.0.1", - "ramda": "^0.26.1", + "ramda": "^0.27.2", "regenerator-runtime": "^0.10.5", "resolve": "^1.5.0", "resolve-dependency-path": "^2.0.0", @@ -72,7 +74,8 @@ "stylus-lookup": "^3.0.2", "typescript": "3.8.3", "user-home": "^2.0.0", - "vue-template-compiler": "^2.5.13" + "vue-template-compiler": "^2.5.13", + "@snyk/protect": "latest" }, "devDependencies": { "@babel/cli": "^7.6.4", @@ -121,5 +124,6 @@ "prettier --write", "git add" ] - } + }, + "snyk": true }