From 5983e82db8a3cade6b72a2e8cdebb635e7016382 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 16 Nov 2017 20:04:58 +0000 Subject: [PATCH 1/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are ignored: - https://snyk.io/vuln/npm:slug:20170907 Latest report for tech4him1/netlify-cms: https://snyk.io/test/github/tech4him1/netlify-cms --- .snyk | 9 +++++++++ package.json | 10 +++++++--- 2 files changed, 16 insertions(+), 3 deletions(-) create mode 100644 .snyk diff --git a/.snyk b/.snyk new file mode 100644 index 000000000000..93d34085517a --- /dev/null +++ b/.snyk @@ -0,0 +1,9 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.8.0 +# ignores vulnerabilities until expiry date; change duration by modifying expiry date +ignore: + 'npm:slug:20170907': + - slug: + reason: None given + expires: '2017-12-16T20:04:56.932Z' +patch: {} diff --git a/package.json b/package.json index 8c311a42db65..f79022f313ab 100644 --- a/package.json +++ b/package.json @@ -21,7 +21,9 @@ "lint:staged": "lint-staged", "deps": "npm-check -s", "deps:update": "npm-check -u", - "prepublishOnly": "npm run build" + "prepublishOnly": "npm run build", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "lint-staged": { "*.js": [ @@ -189,9 +191,11 @@ "unist-builder": "^1.0.2", "unist-util-visit-parents": "^1.1.1", "url": "^0.11.0", - "uuid": "^3.1.0" + "uuid": "^3.1.0", + "snyk": "^1.49.3" }, "optionalDependencies": { "fsevents": "^1.0.14" - } + }, + "snyk": true } From 46a04cab6722acf5b5b437d5181dc0ba4ff46911 Mon Sep 17 00:00:00 2001 From: Caleb Date: Thu, 16 Nov 2017 13:06:06 -0700 Subject: [PATCH 2/2] Update .snyk --- .snyk | 6 ------ 1 file changed, 6 deletions(-) diff --git a/.snyk b/.snyk index 93d34085517a..3e141d833ac6 100644 --- a/.snyk +++ b/.snyk @@ -1,9 +1,3 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. version: v1.8.0 -# ignores vulnerabilities until expiry date; change duration by modifying expiry date -ignore: - 'npm:slug:20170907': - - slug: - reason: None given - expires: '2017-12-16T20:04:56.932Z' patch: {}