From 6dfa9d6abcf15082d4a1a7e988a5bd883edf93f7 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 00:15:41 +0300 Subject: [PATCH 1/2] fix: app/package.json & app/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- app/package.json | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/app/package.json b/app/package.json index e919a44..637c4f0 100644 --- a/app/package.json +++ b/app/package.json @@ -4,13 +4,17 @@ "description": "", "main": "wdio.conf.js", "scripts": { - "test": "wdio wdio.conf.js" + "test": "wdio wdio.conf.js", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "author": "", "license": "ISC", "dependencies": { "wdio-mocha-framework": "^0.5.8", "wdio-teamcity-reporter": "^1.1.1", - "webdriverio": "^4.6.2" - } + "webdriverio": "^4.6.2", + "snyk": "^1.316.1" + }, + "snyk": true } From 61f9f2efe790bf97ed5192191d54a8de099bc7f3 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 1 May 2020 00:15:42 +0300 Subject: [PATCH 2/2] fix: app/package.json & app/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- app/.snyk | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 app/.snyk diff --git a/app/.snyk b/app/.snyk new file mode 100644 index 0000000..378f1b6 --- /dev/null +++ b/app/.snyk @@ -0,0 +1,20 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - wdio-teamcity-reporter > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > archiver > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > inquirer > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > archiver > archiver-utils > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > archiver > zip-stream > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > archiver > zip-stream > archiver-utils > lodash: + patched: '2020-04-30T21:15:39.453Z' + - webdriverio > gaze > globule > lodash: + patched: '2020-04-30T21:15:39.453Z'