diff --git a/.snyk b/.snyk index 61b023e..7d061fb 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.13.5 +version: v1.14.0 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -87,3 +87,6 @@ patch: patched: '2019-10-04T01:06:11.331Z' - snyk > proxy-agent > pac-proxy-agent > https-proxy-agent: patched: '2019-10-04T01:06:11.331Z' + SNYK-JS-TREEKILL-536781: + - snyk > snyk-sbt-plugin > tree-kill: + patched: '2019-12-12T01:01:32.150Z' diff --git a/package.json b/package.json index 0b2d7dd..4a3cdfe 100644 --- a/package.json +++ b/package.json @@ -23,7 +23,7 @@ "nuxt": "^2.0.0", "s-ago": "^1.3.0", "sass-loader": "^7.0.3", - "snyk": "^1.231.0", + "snyk": "^1.258.2", "vue": "^2.5.22", "vue-lazyload": "^1.2.6", "vue-numeral-filter": "^1.1.1", @@ -41,7 +41,7 @@ "test:cypress": "cypress run", "wait": "wait-on http://localhost:3000", "snyk-protect": "snyk protect", - "prepublish": "npm run snyk-protect" + "prepublish": "yarn run snyk-protect" }, "devDependencies": { "@nuxtjs/vuetify": "^1.9.0", diff --git a/yarn.lock b/yarn.lock index ae92798..227c745 100644 --- a/yarn.lock +++ b/yarn.lock @@ -1037,10 +1037,17 @@ dependencies: tslib "^1.9.3" -"@snyk/cocoapods-lockfile-parser@2.0.4": - version "2.0.4" - resolved "https://registry.yarnpkg.com/@snyk/cocoapods-lockfile-parser/-/cocoapods-lockfile-parser-2.0.4.tgz#296421454ba2ee9248ce1f13da57aa1b10b54de7" - integrity sha512-d57bajPjqCiNXMuyMmt9Zt98zbjABZUFw+91B705flzV6oB7OThgtA40Eoin6iatYoStIx28bC3T6b0mScy/iA== +"@snyk/cli-interface@2.3.0": + version "2.3.0" + resolved "https://registry.yarnpkg.com/@snyk/cli-interface/-/cli-interface-2.3.0.tgz#9d38f815a5cf2be266006954c2a058463d531e08" + integrity sha512-ecbylK5Ol2ySb/WbfPj0s0GuLQR+KWKFzUgVaoNHaSoN6371qRWwf2uVr+hPUP4gXqCai21Ug/RDArfOhlPwrQ== + dependencies: + tslib "^1.9.3" + +"@snyk/cocoapods-lockfile-parser@3.0.0": + version "3.0.0" + resolved "https://registry.yarnpkg.com/@snyk/cocoapods-lockfile-parser/-/cocoapods-lockfile-parser-3.0.0.tgz#514b744cedd9d3d3efb2a5d06fce1662fec2ff1a" + integrity sha512-AebCc+v9vtOL9tFkU4/tommgVsXxqdx6t45kCkBW+FC4PaYvfYEg9Eg/9GqlY9+nFrLFo/uTr+E/aR0AF/KqYA== dependencies: "@snyk/dep-graph" "^1.11.0" "@snyk/ruby-semver" "^2.0.4" @@ -1050,25 +1057,13 @@ source-map-support "^0.5.7" tslib "^1.9.3" -"@snyk/composer-lockfile-parser@1.0.3": - version "1.0.3" - resolved "https://registry.yarnpkg.com/@snyk/composer-lockfile-parser/-/composer-lockfile-parser-1.0.3.tgz#4b703883ec36f3cec63c64355031e06698c771f5" - integrity sha512-hb+6E7kMzWlcwfe//ILDoktBPKL2a3+RnJT/CXnzRXaiLQpsdkf5li4q2v0fmvd+4v7L3tTN8KM+//lJyviEkg== +"@snyk/composer-lockfile-parser@1.2.0": + version "1.2.0" + resolved "https://registry.yarnpkg.com/@snyk/composer-lockfile-parser/-/composer-lockfile-parser-1.2.0.tgz#62c6d88c6a39c55dda591854f5380923a993182f" + integrity sha512-kZT+HTqgNcQMeoE5NM9M3jj463M8zI7ZxqZXLw9WoyVs5JTt9g0qFWxIG1cNwZdGVI+y7tzZbNWw9BlMD1vCCQ== dependencies: lodash "^4.17.13" -"@snyk/dep-graph@1.13.0": - version "1.13.0" - resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.0.tgz#855f628da0b833dd16c02c2f977507bbf090b894" - integrity sha512-e0XcLH6Kgs/lunf6iDjbxEnm9+JYFEJn6eo/PlEUW+SMWBZ2uEXHBTDNp9oxjJou48PngzWMveEkniBAN+ulOQ== - dependencies: - graphlib "^2.1.5" - lodash "^4.7.14" - object-hash "^1.3.1" - semver "^6.0.0" - source-map-support "^0.5.11" - tslib "^1.9.3" - "@snyk/dep-graph@1.13.1", "@snyk/dep-graph@^1.11.0": version "1.13.1" resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.1.tgz#45721f7e21136b62d1cdd99b3319e717d9071dfb" @@ -1081,6 +1076,18 @@ source-map-support "^0.5.11" tslib "^1.9.3" +"@snyk/dep-graph@^1.13.1": + version "1.15.0" + resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.15.0.tgz#67bf790bc9f0eee36ad7dad053465cdd928ce223" + integrity sha512-GdF/dvqfKRVHqQio/tSkR4GRpAqIglLPEDZ+XlV7jT5btq9+Fxq2h25Lmm/a7sw+ODTOOqNhTF9y8ASc9VIhww== + dependencies: + graphlib "^2.1.5" + lodash "^4.7.14" + object-hash "^1.3.1" + semver "^6.0.0" + source-map-support "^0.5.11" + tslib "^1.10.0" + "@snyk/gemfile@1.2.0": version "1.2.0" resolved "https://registry.yarnpkg.com/@snyk/gemfile/-/gemfile-1.2.0.tgz#919857944973cce74c650e5428aaf11bcd5c0457" @@ -1093,14 +1100,14 @@ dependencies: lodash "^4.17.14" -"@snyk/snyk-cocoapods-plugin@1.0.3": - version "1.0.3" - resolved "https://registry.yarnpkg.com/@snyk/snyk-cocoapods-plugin/-/snyk-cocoapods-plugin-1.0.3.tgz#eb685590e6a478e1d86f1042c9493426f2f9764a" - integrity sha512-AHAA7z23nPi1eHODsDxeSkl73Ze3yphuqJjMl39ie323EzBDcb9g6uAACrk0Qn2K/K2D8uyxMAf2zDtc+JGQfw== +"@snyk/snyk-cocoapods-plugin@2.0.1": + version "2.0.1" + resolved "https://registry.yarnpkg.com/@snyk/snyk-cocoapods-plugin/-/snyk-cocoapods-plugin-2.0.1.tgz#be8660c854d551a56baa9d072bb4ae7f188cc1cd" + integrity sha512-XVkvaMvMzQ3miJi/YZmsRJSAUfDloYhfg6pXPgzAeAugB4p+cNi01Z68pT62ypB8U/Ugh1Xx2pb9aoOFqBbSjA== dependencies: "@snyk/cli-interface" "1.5.0" - "@snyk/cocoapods-lockfile-parser" "2.0.4" - "@snyk/dep-graph" "1.13.0" + "@snyk/cocoapods-lockfile-parser" "3.0.0" + "@snyk/dep-graph" "^1.13.1" source-map-support "^0.5.7" tslib "^1.9.3" @@ -6228,7 +6235,7 @@ nconf@^0.10.0: secure-keys "^1.0.0" yargs "^3.19.0" -needle@^2.2.1, needle@^2.2.4: +needle@^2.2.1, needle@^2.2.4, needle@^2.4.0: version "2.4.0" resolved "https://registry.yarnpkg.com/needle/-/needle-2.4.0.tgz#6833e74975c444642590e15a750288c5f939b57c" integrity sha512-4Hnwzr3mi5L97hMYeNl8wRW/Onhy4nUKR/lVemJ8gJedxxUyBLm9kkrDColJvoSfwi0jCNhD+xCdOtiGDQiRZg== @@ -8658,10 +8665,10 @@ snyk-go-plugin@1.11.1: tmp "0.0.33" tslib "^1.10.0" -snyk-gradle-plugin@3.2.0: - version "3.2.0" - resolved "https://registry.yarnpkg.com/snyk-gradle-plugin/-/snyk-gradle-plugin-3.2.0.tgz#eb5ae694658c8b3674402622980bcc82bad638a5" - integrity sha512-0fopfp3g7xzs2D20pQBZgP2x4jugyr0cASv/Px3WEfsQR+bJlfk6h67euhH24lOl0fhdTYfz4oiteWPskb39sg== +snyk-gradle-plugin@3.2.2: + version "3.2.2" + resolved "https://registry.yarnpkg.com/snyk-gradle-plugin/-/snyk-gradle-plugin-3.2.2.tgz#703484bec39390d8bd9ca89a408deb77fd63122a" + integrity sha512-ijIWsypbtpdTuRcYTFsnEWbaBnhCc7q0iIg0A4OcOW/xLyInPwyfBMnip4ubNfHAS/PrvzgfwwwJhttcQD0ZaQ== dependencies: "@snyk/cli-interface" "2.2.0" "@types/debug" "^4.1.4" @@ -8679,18 +8686,22 @@ snyk-module@1.9.1, snyk-module@^1.6.0, snyk-module@^1.9.1: debug "^3.1.0" hosted-git-info "^2.7.1" -snyk-mvn-plugin@2.4.0: - version "2.4.0" - resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.4.0.tgz#b653050a4095feccffc1b9387dc3a3f2f1aa69da" - integrity sha512-Fmt6Mjx6zZz+4q6PnBkhuNGhEX++q/pKMI26ls4p3JPkx4KxBz89oncpkmf7P8YCkoaka8oHhtDEv/R4Z9LleQ== +snyk-mvn-plugin@2.7.0: + version "2.7.0" + resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.7.0.tgz#39996df2a878b16a7e3cbe5b63a7c43855031d49" + integrity sha512-DLBt+6ZvtoleXE7Si3wAa6gdPSWsXdIQEY6m2zW2InN9WiaRwIEKMCY822eFmRPZVNNmZNRUIeQsoHZwv/slqQ== dependencies: + "@snyk/cli-interface" "2.2.0" + debug "^4.1.1" lodash "^4.17.15" + needle "^2.4.0" + tmp "^0.1.0" tslib "1.9.3" -snyk-nodejs-lockfile-parser@1.16.0: - version "1.16.0" - resolved "https://registry.yarnpkg.com/snyk-nodejs-lockfile-parser/-/snyk-nodejs-lockfile-parser-1.16.0.tgz#1c1d0aba4643830901ef999415816e7a92b0974d" - integrity sha512-cf3uozRXEG88nsjOQlo+SfOJPpcLs45qpnuk2vhBBZ577IMnV+fTOJQsP2YRiikLUbdgkVlduviwUO6OVn1PhA== +snyk-nodejs-lockfile-parser@1.16.1: + version "1.16.1" + resolved "https://registry.yarnpkg.com/snyk-nodejs-lockfile-parser/-/snyk-nodejs-lockfile-parser-1.16.1.tgz#4a4b38b92dbb7e8935dcce61976a69a00b6747b6" + integrity sha512-MEQImB2XU35D66wYve6g1RcDuD9vyoxGvYtM+ngSd5ItujzjIpyF26W7niqHwBRGLamqjsKF5cOlbmHs+wsx/Q== dependencies: "@yarnpkg/lockfile" "^1.0.2" graphlib "^2.1.5" @@ -8719,12 +8730,13 @@ snyk-paket-parser@1.5.0: dependencies: tslib "^1.9.3" -snyk-php-plugin@1.6.4: - version "1.6.4" - resolved "https://registry.yarnpkg.com/snyk-php-plugin/-/snyk-php-plugin-1.6.4.tgz#c3470aea2f185d2f3417cfc5e966ecf7fd1efa20" - integrity sha512-FFQeimtbwq17nDUS0o0zuKgyjXSX7SpoC9iYTeKvxTXrmKf2QlxTtPvmMM4/hQxehEu1i40ow1Ozw0Ahxm8Dpw== +snyk-php-plugin@1.7.0: + version "1.7.0" + resolved "https://registry.yarnpkg.com/snyk-php-plugin/-/snyk-php-plugin-1.7.0.tgz#cf1906ed8a10db134c803be3d6e4be0cbdc5fe33" + integrity sha512-mDe90xkqSEVrpx1ZC7ItqCOc6fZCySbE+pHVI+dAPUmf1C1LSWZrZVmAVeo/Dw9sJzJfzmcdAFQl+jZP8/uV0A== dependencies: - "@snyk/composer-lockfile-parser" "1.0.3" + "@snyk/cli-interface" "2.2.0" + "@snyk/composer-lockfile-parser" "1.2.0" tslib "1.9.3" snyk-policy@1.13.5: @@ -8742,10 +8754,10 @@ snyk-policy@1.13.5: snyk-try-require "^1.3.1" then-fs "^2.0.0" -snyk-python-plugin@^1.13.3: - version "1.13.3" - resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.13.3.tgz#34587001de2cca8fb400f3f21110c29b39a80e83" - integrity sha512-Ud7mHmpMG4uCChvYLx5jA8HwOV/FNpT65xTxSt+6wsOjIUTuLiqM86mbvgzgk3pir8vMP9yQEsCi1i0zYLBArw== +snyk-python-plugin@^1.14.0: + version "1.14.1" + resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.14.1.tgz#ca512cce83757b2231b9aea6caa3590ac7775bef" + integrity sha512-76u10VrYJp0tz7eD7DC5/Q3fBMPlLieOqoUbN67u0OqF1nF7BLnFBnakZ9VbOqYeJyBoloL9+HIMJ5Nma9qLCQ== dependencies: "@snyk/cli-interface" "^2.0.3" tmp "0.0.33" @@ -8781,14 +8793,14 @@ snyk-resolve@1.0.1, snyk-resolve@^1.0.0, snyk-resolve@^1.0.1: debug "^3.1.0" then-fs "^2.0.0" -snyk-sbt-plugin@2.8.0: - version "2.8.0" - resolved "https://registry.yarnpkg.com/snyk-sbt-plugin/-/snyk-sbt-plugin-2.8.0.tgz#6812e1df1c311e99a7aa565559032c7511d1e4d4" - integrity sha512-ZzyBdND5CsaO0xkv05geZXu8Dd6Llvr/5oTj811U7h7UmrvljrAiABW4RGjRJPrPVuuJaDej2p633sgGtK9UsA== +snyk-sbt-plugin@2.9.1: + version "2.9.1" + resolved "https://registry.yarnpkg.com/snyk-sbt-plugin/-/snyk-sbt-plugin-2.9.1.tgz#41f90f6c318b4657d8bf0cb0ed6856ba0518880f" + integrity sha512-+cRFH4uAaoW7NeVLaWmpU236uhe4JRBakNGe+M9UhAswEqDAyFmyzWVU57EAjlzJKLIdh9JPFUvzjntGNs1I1A== dependencies: + debug "^4.1.1" semver "^6.1.2" tmp "^0.1.0" - tree-kill "^1.2.1" tslib "^1.10.0" snyk-tree@^1.0.0: @@ -8808,15 +8820,15 @@ snyk-try-require@1.3.1, snyk-try-require@^1.1.1, snyk-try-require@^1.3.1: lru-cache "^4.0.0" then-fs "^2.0.0" -snyk@^1.231.0: - version "1.241.0" - resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.241.0.tgz#cf9c3cf042dd1a1f5ac60d4c87574f414a9f0aac" - integrity sha512-LSlh1PCZhEtuZE4Y2/o/ZqLMgIKwiGu0BLMzMQrgMHuNthNCE4DfrmDFPReLHzjCTL8NZ+QhdqWpjqfvgYIsOw== +snyk@^1.258.2: + version "1.258.2" + resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.258.2.tgz#ef26ee26dc11c141c1b646e219a91b93eb5370f8" + integrity sha512-SGVl7Wk82YFhemPuJQZvFkNdSefe6HAQcEbXp4AotwPiYPSP0wLNVuOPlKWakOduBB7/zEAZltRL2+0dv23txQ== dependencies: - "@snyk/cli-interface" "2.2.0" + "@snyk/cli-interface" "2.3.0" "@snyk/dep-graph" "1.13.1" "@snyk/gemfile" "1.2.0" - "@snyk/snyk-cocoapods-plugin" "1.0.3" + "@snyk/snyk-cocoapods-plugin" "2.0.1" "@types/agent-base" "^4.2.0" "@types/restify" "^4.3.6" abbrev "^1.1.1" @@ -8839,17 +8851,17 @@ snyk@^1.231.0: snyk-config "^2.2.1" snyk-docker-plugin "1.33.1" snyk-go-plugin "1.11.1" - snyk-gradle-plugin "3.2.0" + snyk-gradle-plugin "3.2.2" snyk-module "1.9.1" - snyk-mvn-plugin "2.4.0" - snyk-nodejs-lockfile-parser "1.16.0" + snyk-mvn-plugin "2.7.0" + snyk-nodejs-lockfile-parser "1.16.1" snyk-nuget-plugin "1.13.1" - snyk-php-plugin "1.6.4" + snyk-php-plugin "1.7.0" snyk-policy "1.13.5" - snyk-python-plugin "^1.13.3" + snyk-python-plugin "^1.14.0" snyk-resolve "1.0.1" snyk-resolve-deps "4.4.0" - snyk-sbt-plugin "2.8.0" + snyk-sbt-plugin "2.9.1" snyk-tree "^1.0.0" snyk-try-require "1.3.1" source-map-support "^0.5.11" @@ -9558,11 +9570,6 @@ tough-cookie@~2.4.3: psl "^1.1.24" punycode "^1.4.1" -tree-kill@^1.2.1: - version "1.2.1" - resolved "https://registry.yarnpkg.com/tree-kill/-/tree-kill-1.2.1.tgz#5398f374e2f292b9dcc7b2e71e30a5c3bb6c743a" - integrity sha512-4hjqbObwlh2dLyW4tcz0Ymw0ggoaVDMveUB9w8kFSQScdRLo0gxO9J7WFcUBo+W3C1TLdFIEwNOWebgZZ0RH9Q== - trim-newlines@^1.0.0: version "1.0.0" resolved "https://registry.yarnpkg.com/trim-newlines/-/trim-newlines-1.0.0.tgz#5887966bb582a4503a41eb524f7d35011815a613"