diff --git a/.snyk b/.snyk index 88ba614..67a08de 100644 --- a/.snyk +++ b/.snyk @@ -1,4 +1,8 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.13.1 +version: v1.14.1 ignore: {} -patch: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - lodash: + patched: '2020-04-30T23:33:27.947Z' diff --git a/package.json b/package.json index 644cc2d..5bd8c8a 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,8 @@ "scope": "\\S+.*" }, "dependencies": { - "lodash": "^4.17.4" + "lodash": "^4.17.4", + "snyk": "^1.316.1" }, "devDependencies": { "@babel/core": "^7.1.6", @@ -63,7 +64,6 @@ "markdown-toc": "^1.2.0", "prettier": "^1.15.2", "semantic-release": "^15.12.2", - "snyk": "^1.110.2", "sonar-scanner": "^3.1.0", "standard-version": "^4.4.0", "swagger-parser": "^6.0.2", @@ -129,6 +129,9 @@ "security:snyk:monitor": "snyk monitor --org=commonality", "security:snyk:scan": "snyk test", "standard-version": "standard-version", - "test": "jest --config=jest.config.json --forceExit" - } + "test": "jest --config=jest.config.json --forceExit", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" + }, + "snyk": true }