From 0efda2b2747fc3a6e2ee6569cb45f91dbd1b7495 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 3 May 2020 00:13:00 +0200 Subject: [PATCH 1/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index d57a086..9c1aeac 100644 --- a/package.json +++ b/package.json @@ -28,7 +28,7 @@ "mosca": "^2.1.0", "setprototypeof": "^1.0.1", "winston": "^2.1.0", - "snyk": "^1.25.0" + "snyk": "^1.316.2" }, "devDependencies": { "chokidar": "^1.2.0", From da1aa1ac07de75c648104fb671803f7c75c6e189 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 3 May 2020 00:13:01 +0200 Subject: [PATCH 2/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.snyk b/.snyk index 260973d..2b63b68 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.7.0 +version: v1.14.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -11,3 +11,10 @@ patch: patched: '2017-02-18T10:10:46.080Z' - csweb > hypertimer > ws: patched: '2017-02-18T10:10:46.080Z' + SNYK-JS-LODASH-567746: + - mosca > amqp > lodash: + patched: '2020-05-02T22:12:57.369Z' + - mosca > ascoltatori > amqp > lodash: + patched: '2020-05-02T22:12:57.369Z' + - mosca > ascoltatori > ioredis > lodash: + patched: '2020-05-02T22:12:57.369Z'