Merge branch 'snyk-fix-fe1f256ed1013bc62aaf097aa3fbc286' into 'master'

[Snyk] Fix for 1 vulnerabilities

See merge request unboundsoftware/dancefinder/dancefinder-app!7
This commit was merged in pull request #56.
This commit is contained in:
2019-12-12 05:38:45 +00:00
3 changed files with 83 additions and 73 deletions
+4 -1
View File
@@ -1,5 +1,5 @@
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
version: v1.13.5 version: v1.14.0
ignore: {} ignore: {}
# patches apply the minimum changes required to fix a vulnerability # patches apply the minimum changes required to fix a vulnerability
patch: patch:
@@ -87,3 +87,6 @@ patch:
patched: '2019-10-04T01:06:11.331Z' patched: '2019-10-04T01:06:11.331Z'
- snyk > proxy-agent > pac-proxy-agent > https-proxy-agent: - snyk > proxy-agent > pac-proxy-agent > https-proxy-agent:
patched: '2019-10-04T01:06:11.331Z' patched: '2019-10-04T01:06:11.331Z'
SNYK-JS-TREEKILL-536781:
- snyk > snyk-sbt-plugin > tree-kill:
patched: '2019-12-12T01:01:32.150Z'
+2 -2
View File
@@ -23,7 +23,7 @@
"nuxt": "^2.0.0", "nuxt": "^2.0.0",
"s-ago": "^1.3.0", "s-ago": "^1.3.0",
"sass-loader": "^7.0.3", "sass-loader": "^7.0.3",
"snyk": "^1.231.0", "snyk": "^1.258.2",
"vue": "^2.5.22", "vue": "^2.5.22",
"vue-lazyload": "^1.2.6", "vue-lazyload": "^1.2.6",
"vue-numeral-filter": "^1.1.1", "vue-numeral-filter": "^1.1.1",
@@ -41,7 +41,7 @@
"test:cypress": "cypress run", "test:cypress": "cypress run",
"wait": "wait-on http://localhost:3000", "wait": "wait-on http://localhost:3000",
"snyk-protect": "snyk protect", "snyk-protect": "snyk protect",
"prepublish": "npm run snyk-protect" "prepublish": "yarn run snyk-protect"
}, },
"devDependencies": { "devDependencies": {
"@nuxtjs/vuetify": "^1.9.0", "@nuxtjs/vuetify": "^1.9.0",
+77 -70
View File
@@ -1037,10 +1037,17 @@
dependencies: dependencies:
tslib "^1.9.3" tslib "^1.9.3"
"@snyk/cocoapods-lockfile-parser@2.0.4": "@snyk/cli-interface@2.3.0":
version "2.0.4" version "2.3.0"
resolved "https://registry.yarnpkg.com/@snyk/cocoapods-lockfile-parser/-/cocoapods-lockfile-parser-2.0.4.tgz#296421454ba2ee9248ce1f13da57aa1b10b54de7" resolved "https://registry.yarnpkg.com/@snyk/cli-interface/-/cli-interface-2.3.0.tgz#9d38f815a5cf2be266006954c2a058463d531e08"
integrity sha512-d57bajPjqCiNXMuyMmt9Zt98zbjABZUFw+91B705flzV6oB7OThgtA40Eoin6iatYoStIx28bC3T6b0mScy/iA== integrity sha512-ecbylK5Ol2ySb/WbfPj0s0GuLQR+KWKFzUgVaoNHaSoN6371qRWwf2uVr+hPUP4gXqCai21Ug/RDArfOhlPwrQ==
dependencies:
tslib "^1.9.3"
"@snyk/cocoapods-lockfile-parser@3.0.0":
version "3.0.0"
resolved "https://registry.yarnpkg.com/@snyk/cocoapods-lockfile-parser/-/cocoapods-lockfile-parser-3.0.0.tgz#514b744cedd9d3d3efb2a5d06fce1662fec2ff1a"
integrity sha512-AebCc+v9vtOL9tFkU4/tommgVsXxqdx6t45kCkBW+FC4PaYvfYEg9Eg/9GqlY9+nFrLFo/uTr+E/aR0AF/KqYA==
dependencies: dependencies:
"@snyk/dep-graph" "^1.11.0" "@snyk/dep-graph" "^1.11.0"
"@snyk/ruby-semver" "^2.0.4" "@snyk/ruby-semver" "^2.0.4"
@@ -1050,25 +1057,13 @@
source-map-support "^0.5.7" source-map-support "^0.5.7"
tslib "^1.9.3" tslib "^1.9.3"
"@snyk/composer-lockfile-parser@1.0.3": "@snyk/composer-lockfile-parser@1.2.0":
version "1.0.3" version "1.2.0"
resolved "https://registry.yarnpkg.com/@snyk/composer-lockfile-parser/-/composer-lockfile-parser-1.0.3.tgz#4b703883ec36f3cec63c64355031e06698c771f5" resolved "https://registry.yarnpkg.com/@snyk/composer-lockfile-parser/-/composer-lockfile-parser-1.2.0.tgz#62c6d88c6a39c55dda591854f5380923a993182f"
integrity sha512-hb+6E7kMzWlcwfe//ILDoktBPKL2a3+RnJT/CXnzRXaiLQpsdkf5li4q2v0fmvd+4v7L3tTN8KM+//lJyviEkg== integrity sha512-kZT+HTqgNcQMeoE5NM9M3jj463M8zI7ZxqZXLw9WoyVs5JTt9g0qFWxIG1cNwZdGVI+y7tzZbNWw9BlMD1vCCQ==
dependencies: dependencies:
lodash "^4.17.13" lodash "^4.17.13"
"@snyk/dep-graph@1.13.0":
version "1.13.0"
resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.0.tgz#855f628da0b833dd16c02c2f977507bbf090b894"
integrity sha512-e0XcLH6Kgs/lunf6iDjbxEnm9+JYFEJn6eo/PlEUW+SMWBZ2uEXHBTDNp9oxjJou48PngzWMveEkniBAN+ulOQ==
dependencies:
graphlib "^2.1.5"
lodash "^4.7.14"
object-hash "^1.3.1"
semver "^6.0.0"
source-map-support "^0.5.11"
tslib "^1.9.3"
"@snyk/dep-graph@1.13.1", "@snyk/dep-graph@^1.11.0": "@snyk/dep-graph@1.13.1", "@snyk/dep-graph@^1.11.0":
version "1.13.1" version "1.13.1"
resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.1.tgz#45721f7e21136b62d1cdd99b3319e717d9071dfb" resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.13.1.tgz#45721f7e21136b62d1cdd99b3319e717d9071dfb"
@@ -1081,6 +1076,18 @@
source-map-support "^0.5.11" source-map-support "^0.5.11"
tslib "^1.9.3" tslib "^1.9.3"
"@snyk/dep-graph@^1.13.1":
version "1.15.0"
resolved "https://registry.yarnpkg.com/@snyk/dep-graph/-/dep-graph-1.15.0.tgz#67bf790bc9f0eee36ad7dad053465cdd928ce223"
integrity sha512-GdF/dvqfKRVHqQio/tSkR4GRpAqIglLPEDZ+XlV7jT5btq9+Fxq2h25Lmm/a7sw+ODTOOqNhTF9y8ASc9VIhww==
dependencies:
graphlib "^2.1.5"
lodash "^4.7.14"
object-hash "^1.3.1"
semver "^6.0.0"
source-map-support "^0.5.11"
tslib "^1.10.0"
"@snyk/gemfile@1.2.0": "@snyk/gemfile@1.2.0":
version "1.2.0" version "1.2.0"
resolved "https://registry.yarnpkg.com/@snyk/gemfile/-/gemfile-1.2.0.tgz#919857944973cce74c650e5428aaf11bcd5c0457" resolved "https://registry.yarnpkg.com/@snyk/gemfile/-/gemfile-1.2.0.tgz#919857944973cce74c650e5428aaf11bcd5c0457"
@@ -1093,14 +1100,14 @@
dependencies: dependencies:
lodash "^4.17.14" lodash "^4.17.14"
"@snyk/snyk-cocoapods-plugin@1.0.3": "@snyk/snyk-cocoapods-plugin@2.0.1":
version "1.0.3" version "2.0.1"
resolved "https://registry.yarnpkg.com/@snyk/snyk-cocoapods-plugin/-/snyk-cocoapods-plugin-1.0.3.tgz#eb685590e6a478e1d86f1042c9493426f2f9764a" resolved "https://registry.yarnpkg.com/@snyk/snyk-cocoapods-plugin/-/snyk-cocoapods-plugin-2.0.1.tgz#be8660c854d551a56baa9d072bb4ae7f188cc1cd"
integrity sha512-AHAA7z23nPi1eHODsDxeSkl73Ze3yphuqJjMl39ie323EzBDcb9g6uAACrk0Qn2K/K2D8uyxMAf2zDtc+JGQfw== integrity sha512-XVkvaMvMzQ3miJi/YZmsRJSAUfDloYhfg6pXPgzAeAugB4p+cNi01Z68pT62ypB8U/Ugh1Xx2pb9aoOFqBbSjA==
dependencies: dependencies:
"@snyk/cli-interface" "1.5.0" "@snyk/cli-interface" "1.5.0"
"@snyk/cocoapods-lockfile-parser" "2.0.4" "@snyk/cocoapods-lockfile-parser" "3.0.0"
"@snyk/dep-graph" "1.13.0" "@snyk/dep-graph" "^1.13.1"
source-map-support "^0.5.7" source-map-support "^0.5.7"
tslib "^1.9.3" tslib "^1.9.3"
@@ -6228,7 +6235,7 @@ nconf@^0.10.0:
secure-keys "^1.0.0" secure-keys "^1.0.0"
yargs "^3.19.0" yargs "^3.19.0"
needle@^2.2.1, needle@^2.2.4: needle@^2.2.1, needle@^2.2.4, needle@^2.4.0:
version "2.4.0" version "2.4.0"
resolved "https://registry.yarnpkg.com/needle/-/needle-2.4.0.tgz#6833e74975c444642590e15a750288c5f939b57c" resolved "https://registry.yarnpkg.com/needle/-/needle-2.4.0.tgz#6833e74975c444642590e15a750288c5f939b57c"
integrity sha512-4Hnwzr3mi5L97hMYeNl8wRW/Onhy4nUKR/lVemJ8gJedxxUyBLm9kkrDColJvoSfwi0jCNhD+xCdOtiGDQiRZg== integrity sha512-4Hnwzr3mi5L97hMYeNl8wRW/Onhy4nUKR/lVemJ8gJedxxUyBLm9kkrDColJvoSfwi0jCNhD+xCdOtiGDQiRZg==
@@ -8658,10 +8665,10 @@ snyk-go-plugin@1.11.1:
tmp "0.0.33" tmp "0.0.33"
tslib "^1.10.0" tslib "^1.10.0"
snyk-gradle-plugin@3.2.0: snyk-gradle-plugin@3.2.2:
version "3.2.0" version "3.2.2"
resolved "https://registry.yarnpkg.com/snyk-gradle-plugin/-/snyk-gradle-plugin-3.2.0.tgz#eb5ae694658c8b3674402622980bcc82bad638a5" resolved "https://registry.yarnpkg.com/snyk-gradle-plugin/-/snyk-gradle-plugin-3.2.2.tgz#703484bec39390d8bd9ca89a408deb77fd63122a"
integrity sha512-0fopfp3g7xzs2D20pQBZgP2x4jugyr0cASv/Px3WEfsQR+bJlfk6h67euhH24lOl0fhdTYfz4oiteWPskb39sg== integrity sha512-ijIWsypbtpdTuRcYTFsnEWbaBnhCc7q0iIg0A4OcOW/xLyInPwyfBMnip4ubNfHAS/PrvzgfwwwJhttcQD0ZaQ==
dependencies: dependencies:
"@snyk/cli-interface" "2.2.0" "@snyk/cli-interface" "2.2.0"
"@types/debug" "^4.1.4" "@types/debug" "^4.1.4"
@@ -8679,18 +8686,22 @@ snyk-module@1.9.1, snyk-module@^1.6.0, snyk-module@^1.9.1:
debug "^3.1.0" debug "^3.1.0"
hosted-git-info "^2.7.1" hosted-git-info "^2.7.1"
snyk-mvn-plugin@2.4.0: snyk-mvn-plugin@2.7.0:
version "2.4.0" version "2.7.0"
resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.4.0.tgz#b653050a4095feccffc1b9387dc3a3f2f1aa69da" resolved "https://registry.yarnpkg.com/snyk-mvn-plugin/-/snyk-mvn-plugin-2.7.0.tgz#39996df2a878b16a7e3cbe5b63a7c43855031d49"
integrity sha512-Fmt6Mjx6zZz+4q6PnBkhuNGhEX++q/pKMI26ls4p3JPkx4KxBz89oncpkmf7P8YCkoaka8oHhtDEv/R4Z9LleQ== integrity sha512-DLBt+6ZvtoleXE7Si3wAa6gdPSWsXdIQEY6m2zW2InN9WiaRwIEKMCY822eFmRPZVNNmZNRUIeQsoHZwv/slqQ==
dependencies: dependencies:
"@snyk/cli-interface" "2.2.0"
debug "^4.1.1"
lodash "^4.17.15" lodash "^4.17.15"
needle "^2.4.0"
tmp "^0.1.0"
tslib "1.9.3" tslib "1.9.3"
snyk-nodejs-lockfile-parser@1.16.0: snyk-nodejs-lockfile-parser@1.16.1:
version "1.16.0" version "1.16.1"
resolved "https://registry.yarnpkg.com/snyk-nodejs-lockfile-parser/-/snyk-nodejs-lockfile-parser-1.16.0.tgz#1c1d0aba4643830901ef999415816e7a92b0974d" resolved "https://registry.yarnpkg.com/snyk-nodejs-lockfile-parser/-/snyk-nodejs-lockfile-parser-1.16.1.tgz#4a4b38b92dbb7e8935dcce61976a69a00b6747b6"
integrity sha512-cf3uozRXEG88nsjOQlo+SfOJPpcLs45qpnuk2vhBBZ577IMnV+fTOJQsP2YRiikLUbdgkVlduviwUO6OVn1PhA== integrity sha512-MEQImB2XU35D66wYve6g1RcDuD9vyoxGvYtM+ngSd5ItujzjIpyF26W7niqHwBRGLamqjsKF5cOlbmHs+wsx/Q==
dependencies: dependencies:
"@yarnpkg/lockfile" "^1.0.2" "@yarnpkg/lockfile" "^1.0.2"
graphlib "^2.1.5" graphlib "^2.1.5"
@@ -8719,12 +8730,13 @@ snyk-paket-parser@1.5.0:
dependencies: dependencies:
tslib "^1.9.3" tslib "^1.9.3"
snyk-php-plugin@1.6.4: snyk-php-plugin@1.7.0:
version "1.6.4" version "1.7.0"
resolved "https://registry.yarnpkg.com/snyk-php-plugin/-/snyk-php-plugin-1.6.4.tgz#c3470aea2f185d2f3417cfc5e966ecf7fd1efa20" resolved "https://registry.yarnpkg.com/snyk-php-plugin/-/snyk-php-plugin-1.7.0.tgz#cf1906ed8a10db134c803be3d6e4be0cbdc5fe33"
integrity sha512-FFQeimtbwq17nDUS0o0zuKgyjXSX7SpoC9iYTeKvxTXrmKf2QlxTtPvmMM4/hQxehEu1i40ow1Ozw0Ahxm8Dpw== integrity sha512-mDe90xkqSEVrpx1ZC7ItqCOc6fZCySbE+pHVI+dAPUmf1C1LSWZrZVmAVeo/Dw9sJzJfzmcdAFQl+jZP8/uV0A==
dependencies: dependencies:
"@snyk/composer-lockfile-parser" "1.0.3" "@snyk/cli-interface" "2.2.0"
"@snyk/composer-lockfile-parser" "1.2.0"
tslib "1.9.3" tslib "1.9.3"
snyk-policy@1.13.5: snyk-policy@1.13.5:
@@ -8742,10 +8754,10 @@ snyk-policy@1.13.5:
snyk-try-require "^1.3.1" snyk-try-require "^1.3.1"
then-fs "^2.0.0" then-fs "^2.0.0"
snyk-python-plugin@^1.13.3: snyk-python-plugin@^1.14.0:
version "1.13.3" version "1.14.1"
resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.13.3.tgz#34587001de2cca8fb400f3f21110c29b39a80e83" resolved "https://registry.yarnpkg.com/snyk-python-plugin/-/snyk-python-plugin-1.14.1.tgz#ca512cce83757b2231b9aea6caa3590ac7775bef"
integrity sha512-Ud7mHmpMG4uCChvYLx5jA8HwOV/FNpT65xTxSt+6wsOjIUTuLiqM86mbvgzgk3pir8vMP9yQEsCi1i0zYLBArw== integrity sha512-76u10VrYJp0tz7eD7DC5/Q3fBMPlLieOqoUbN67u0OqF1nF7BLnFBnakZ9VbOqYeJyBoloL9+HIMJ5Nma9qLCQ==
dependencies: dependencies:
"@snyk/cli-interface" "^2.0.3" "@snyk/cli-interface" "^2.0.3"
tmp "0.0.33" tmp "0.0.33"
@@ -8781,14 +8793,14 @@ snyk-resolve@1.0.1, snyk-resolve@^1.0.0, snyk-resolve@^1.0.1:
debug "^3.1.0" debug "^3.1.0"
then-fs "^2.0.0" then-fs "^2.0.0"
snyk-sbt-plugin@2.8.0: snyk-sbt-plugin@2.9.1:
version "2.8.0" version "2.9.1"
resolved "https://registry.yarnpkg.com/snyk-sbt-plugin/-/snyk-sbt-plugin-2.8.0.tgz#6812e1df1c311e99a7aa565559032c7511d1e4d4" resolved "https://registry.yarnpkg.com/snyk-sbt-plugin/-/snyk-sbt-plugin-2.9.1.tgz#41f90f6c318b4657d8bf0cb0ed6856ba0518880f"
integrity sha512-ZzyBdND5CsaO0xkv05geZXu8Dd6Llvr/5oTj811U7h7UmrvljrAiABW4RGjRJPrPVuuJaDej2p633sgGtK9UsA== integrity sha512-+cRFH4uAaoW7NeVLaWmpU236uhe4JRBakNGe+M9UhAswEqDAyFmyzWVU57EAjlzJKLIdh9JPFUvzjntGNs1I1A==
dependencies: dependencies:
debug "^4.1.1"
semver "^6.1.2" semver "^6.1.2"
tmp "^0.1.0" tmp "^0.1.0"
tree-kill "^1.2.1"
tslib "^1.10.0" tslib "^1.10.0"
snyk-tree@^1.0.0: snyk-tree@^1.0.0:
@@ -8808,15 +8820,15 @@ snyk-try-require@1.3.1, snyk-try-require@^1.1.1, snyk-try-require@^1.3.1:
lru-cache "^4.0.0" lru-cache "^4.0.0"
then-fs "^2.0.0" then-fs "^2.0.0"
snyk@^1.231.0: snyk@^1.258.2:
version "1.241.0" version "1.258.2"
resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.241.0.tgz#cf9c3cf042dd1a1f5ac60d4c87574f414a9f0aac" resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.258.2.tgz#ef26ee26dc11c141c1b646e219a91b93eb5370f8"
integrity sha512-LSlh1PCZhEtuZE4Y2/o/ZqLMgIKwiGu0BLMzMQrgMHuNthNCE4DfrmDFPReLHzjCTL8NZ+QhdqWpjqfvgYIsOw== integrity sha512-SGVl7Wk82YFhemPuJQZvFkNdSefe6HAQcEbXp4AotwPiYPSP0wLNVuOPlKWakOduBB7/zEAZltRL2+0dv23txQ==
dependencies: dependencies:
"@snyk/cli-interface" "2.2.0" "@snyk/cli-interface" "2.3.0"
"@snyk/dep-graph" "1.13.1" "@snyk/dep-graph" "1.13.1"
"@snyk/gemfile" "1.2.0" "@snyk/gemfile" "1.2.0"
"@snyk/snyk-cocoapods-plugin" "1.0.3" "@snyk/snyk-cocoapods-plugin" "2.0.1"
"@types/agent-base" "^4.2.0" "@types/agent-base" "^4.2.0"
"@types/restify" "^4.3.6" "@types/restify" "^4.3.6"
abbrev "^1.1.1" abbrev "^1.1.1"
@@ -8839,17 +8851,17 @@ snyk@^1.231.0:
snyk-config "^2.2.1" snyk-config "^2.2.1"
snyk-docker-plugin "1.33.1" snyk-docker-plugin "1.33.1"
snyk-go-plugin "1.11.1" snyk-go-plugin "1.11.1"
snyk-gradle-plugin "3.2.0" snyk-gradle-plugin "3.2.2"
snyk-module "1.9.1" snyk-module "1.9.1"
snyk-mvn-plugin "2.4.0" snyk-mvn-plugin "2.7.0"
snyk-nodejs-lockfile-parser "1.16.0" snyk-nodejs-lockfile-parser "1.16.1"
snyk-nuget-plugin "1.13.1" snyk-nuget-plugin "1.13.1"
snyk-php-plugin "1.6.4" snyk-php-plugin "1.7.0"
snyk-policy "1.13.5" snyk-policy "1.13.5"
snyk-python-plugin "^1.13.3" snyk-python-plugin "^1.14.0"
snyk-resolve "1.0.1" snyk-resolve "1.0.1"
snyk-resolve-deps "4.4.0" snyk-resolve-deps "4.4.0"
snyk-sbt-plugin "2.8.0" snyk-sbt-plugin "2.9.1"
snyk-tree "^1.0.0" snyk-tree "^1.0.0"
snyk-try-require "1.3.1" snyk-try-require "1.3.1"
source-map-support "^0.5.11" source-map-support "^0.5.11"
@@ -9558,11 +9570,6 @@ tough-cookie@~2.4.3:
psl "^1.1.24" psl "^1.1.24"
punycode "^1.4.1" punycode "^1.4.1"
tree-kill@^1.2.1:
version "1.2.1"
resolved "https://registry.yarnpkg.com/tree-kill/-/tree-kill-1.2.1.tgz#5398f374e2f292b9dcc7b2e71e30a5c3bb6c743a"
integrity sha512-4hjqbObwlh2dLyW4tcz0Ymw0ggoaVDMveUB9w8kFSQScdRLo0gxO9J7WFcUBo+W3C1TLdFIEwNOWebgZZ0RH9Q==
trim-newlines@^1.0.0: trim-newlines@^1.0.0:
version "1.0.0" version "1.0.0"
resolved "https://registry.yarnpkg.com/trim-newlines/-/trim-newlines-1.0.0.tgz#5887966bb582a4503a41eb524f7d35011815a613" resolved "https://registry.yarnpkg.com/trim-newlines/-/trim-newlines-1.0.0.tgz#5887966bb582a4503a41eb524f7d35011815a613"