From e831d4e8ac2ac3cdfdafea386238d8b78571a8ff Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 2 May 2020 22:18:43 -0700 Subject: [PATCH 1/2] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 39 ++++++++++++++++++++++++++++++++++++++- 1 file changed, 38 insertions(+), 1 deletion(-) diff --git a/.snyk b/.snyk index 549d6e1..c94f75b 100644 --- a/.snyk +++ b/.snyk @@ -1,8 +1,45 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.7.1 +version: v1.14.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: 'npm:ms:20170412': - node-rest-client > debug > ms: patched: '2017-05-21T19:00:22.464Z' + SNYK-JS-LODASH-567746: + - lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/dep-graph > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > inquirer > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-config > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-mvn-plugin > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-nodejs-lockfile-parser > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-nuget-plugin > lodash: + patched: '2020-05-03T05:18:40.655Z' + - node-rest-client > xml2js > xmlbuilder > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/dep-graph > graphlib > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-go-plugin > graphlib > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-nodejs-lockfile-parser > graphlib > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/snyk-cocoapods-plugin > @snyk/dep-graph > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-nuget-plugin > dotnet-deps-parser > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > snyk-php-plugin > @snyk/composer-lockfile-parser > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/snyk-cocoapods-plugin > @snyk/dep-graph > graphlib > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/snyk-cocoapods-plugin > @snyk/cocoapods-lockfile-parser > @snyk/ruby-semver > lodash: + patched: '2020-05-03T05:18:40.655Z' + - snyk > @snyk/snyk-cocoapods-plugin > @snyk/cocoapods-lockfile-parser > @snyk/dep-graph > graphlib > lodash: + patched: '2020-05-03T05:18:40.655Z' From a1f69ffc851fa09e11f2ecbc35e357f1cb20c68e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 2 May 2020 22:18:44 -0700 Subject: [PATCH 2/2] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index de5c739..f2fc57a 100644 --- a/package.json +++ b/package.json @@ -7,7 +7,7 @@ "test": "gulp build-test && jasmine", "build": "gulp", "snyk-protect": "snyk protect", - "prepublish": "npm run snyk-protect" + "prepublish": "yarn run snyk-protect" }, "keywords": [ "uiuc", @@ -26,7 +26,7 @@ "dependencies": { "lodash": "^4.7.0", "node-rest-client": "^1.8.0", - "snyk": "^1.30.1" + "snyk": "^1.316.2" }, "repository": "pranaygp/uiuc", "snyk": true