From 0a298df15ec93789e2d2fe062b6c36e83869526b Mon Sep 17 00:00:00 2001 From: Joakim Olsson Date: Thu, 4 Jul 2019 10:52:51 +0000 Subject: [PATCH 1/2] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 --- .snyk | 22 ++++++++++++++++++++++ package.json | 2 +- 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/.snyk b/.snyk index c340bb2..93a15cd 100644 --- a/.snyk +++ b/.snyk @@ -52,3 +52,25 @@ patch: patched: '2019-07-04T01:01:11.312Z' - nuxt > @nuxt/webpack > @nuxt/babel-preset-app > @babel/preset-env > @babel/plugin-proposal-async-generator-functions > @babel/helper-remap-async-to-generator > @babel/helper-wrap-function > @babel/traverse > @babel/helper-function-name > @babel/helper-get-function-arity > @babel/types > lodash: patched: '2019-07-04T01:01:11.312Z' + - snyk > inquirer > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-config > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-nuget-plugin > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2019-07-04T10:52:49.982Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2019-07-04T10:52:49.982Z' diff --git a/package.json b/package.json index 81d75d5..160d90d 100644 --- a/package.json +++ b/package.json @@ -27,7 +27,7 @@ "vue-lazyload": "^1.2.6", "vue-numeral-filter": "^1.1.1", "vuetify": "^1.4.2", - "snyk": "^1.189.0" + "snyk": "^1.191.0" }, "scripts": { "dev": "NODE_ENV=development node server/index.js", -- 2.52.0 From 467c60c17166523d0762ded9b5a6f7234ec5cba8 Mon Sep 17 00:00:00 2001 From: Joakim Olsson Date: Thu, 4 Jul 2019 12:57:17 +0200 Subject: [PATCH 2/2] Update yarn.lock --- yarn.lock | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/yarn.lock b/yarn.lock index c9defa9..337471c 100644 --- a/yarn.lock +++ b/yarn.lock @@ -8473,7 +8473,7 @@ snyk-try-require@1.3.1, snyk-try-require@^1.1.1, snyk-try-require@^1.3.1: lru-cache "^4.0.0" then-fs "^2.0.0" -snyk@^1.189.0: +snyk@^1.191.0: version "1.191.0" resolved "https://registry.yarnpkg.com/snyk/-/snyk-1.191.0.tgz#2a8cae1470e228123d3a77be810603a612518a40" integrity sha512-ql7FkVsvLSIAjrpffLZUS440D3oWcJ107j4F5/rQfDF64qUQ5O4XENTrC+teJeDHQf7zFZc1Xk7szGOK3eF6xg== -- 2.52.0