From bc00ee8d1064a95be9d905fd60955823bb4a454a Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 6 Oct 2022 15:32:39 +0000 Subject: [PATCH] fix: imageboard/package.json & imageboard/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:uglify-js:20151024 --- imageboard/.snyk | 8 ++++++++ imageboard/package.json | 30 ++++++++++++++++++------------ 2 files changed, 26 insertions(+), 12 deletions(-) create mode 100644 imageboard/.snyk diff --git a/imageboard/.snyk b/imageboard/.snyk new file mode 100644 index 0000000..11b0e7d --- /dev/null +++ b/imageboard/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:uglify-js:20151024': + - jade > transformers > uglify-js: + patched: '2022-10-06T15:32:38.484Z' diff --git a/imageboard/package.json b/imageboard/package.json index 723204e..aa620c6 100644 --- a/imageboard/package.json +++ b/imageboard/package.json @@ -1,14 +1,20 @@ { - "name": "imageboard-sample", - "version": "0.0.1", - "private": true, - "dependencies": { - "express": "^4.13.3", - "body-parser": "^1.14.1", - "errorhandler": "^1.4.2", - "method-override": "^2.3.5", - "ejs": ">= 0.5.0", - "jade": ">= 1.11.0", - "mongodb": ">= 1.4.29" - } + "name": "imageboard-sample", + "version": "0.0.1", + "private": true, + "dependencies": { + "express": "^4.13.3", + "body-parser": "^1.14.1", + "errorhandler": "^1.4.2", + "method-override": "^2.3.5", + "ejs": ">= 0.5.0", + "jade": ">= 1.11.0", + "mongodb": ">= 1.4.29", + "@snyk/protect": "latest" + }, + "scripts": { + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" + }, + "snyk": true } \ No newline at end of file