From a1cb03dd73bebd9ddf19bd23ae19611c963f8017 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 30 Aug 2023 16:56:52 +0000 Subject: [PATCH] fix: package.json, yarn.lock & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:extend:20180424 - https://snyk.io/vuln/npm:hoek:20180212 - https://snyk.io/vuln/npm:stringstream:20180511 --- .snyk | 67 +++++++++++++++++++++++++++++++++++++++++++++++++++- package.json | 6 ++--- yarn.lock | 5 ++++ 3 files changed, 74 insertions(+), 4 deletions(-) diff --git a/.snyk b/.snyk index 185dd6b..346a779 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.10.1 +version: v1.25.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -8,3 +8,68 @@ patch: patched: '2018-01-24T16:26:38.614Z' - esdoc-standard-plugin > esdoc-publish-html-plugin > marked: patched: '2018-01-24T16:26:38.614Z' + 'npm:extend:20180424': + - esdoc > ice-cap > cheerio > jsdom > request > extend: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:extend:20180424' + path: esdoc > ice-cap > cheerio > jsdom > request > extend + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > extend: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:extend:20180424' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > extend + 'npm:hoek:20180212': + - esdoc > ice-cap > cheerio > jsdom > request > hawk > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: esdoc > ice-cap > cheerio > jsdom > request > hawk > hoek + - esdoc > ice-cap > cheerio > jsdom > request > hawk > boom > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: esdoc > ice-cap > cheerio > jsdom > request > hawk > boom > hoek + - esdoc > ice-cap > cheerio > jsdom > request > hawk > sntp > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: esdoc > ice-cap > cheerio > jsdom > request > hawk > sntp > hoek + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > hawk > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > hawk > hoek + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > hawk > boom > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > hawk > boom > hoek + - esdoc > ice-cap > cheerio > jsdom > request > hawk > cryptiles > boom > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: >- + esdoc > ice-cap > cheerio > jsdom > request > hawk > cryptiles > boom + > hoek + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > hawk > sntp > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > hawk > sntp > hoek + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > hawk > cryptiles > boom > hoek: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:hoek:20180212' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > hawk > cryptiles > boom > hoek + 'npm:stringstream:20180511': + - esdoc > ice-cap > cheerio > jsdom > request > stringstream: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:stringstream:20180511' + path: esdoc > ice-cap > cheerio > jsdom > request > stringstream + - esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio > jsdom > request > stringstream: + patched: '2023-08-30T16:56:32.978Z' + id: 'npm:stringstream:20180511' + path: >- + esdoc-standard-plugin > esdoc-publish-html-plugin > ice-cap > cheerio + > jsdom > request > stringstream diff --git a/package.json b/package.json index d5293dc..41ac619 100644 --- a/package.json +++ b/package.json @@ -20,8 +20,8 @@ "size": "echo \"Gzipped Size: $(strip-json-comments --no-whitespace dist/nextframe.js | gzip-size)\"", "release": "yarn run build -s && yarn run bump && git push --follow-tags origin master && npm publish", "test": "yarn build && ava -v", - "snyk-protect": "snyk protect", - "prepublish": "npm run snyk-protect" + "snyk-protect": "snyk-protect", + "prepublish": "yarn run snyk-protect" }, "files": [ "dist", @@ -57,7 +57,7 @@ "esdoc-standard-plugin": "^1.0.0", "raf": "^3.4.0", "setimmediate": "^1.0.5", - "snyk": "^*" + "@snyk/protect": "latest" }, "peerDependencies": { "raf": "3.4.0" diff --git a/yarn.lock b/yarn.lock index f3400ab..c8ebd2e 100644 --- a/yarn.lock +++ b/yarn.lock @@ -44,6 +44,11 @@ dependencies: arrify "^1.0.1" +"@snyk/protect@^1.1207.0": + version "1.1207.0" + resolved "https://registry.yarnpkg.com/@snyk/protect/-/protect-1.1207.0.tgz#1fa34a07987100b43faf94e04aaaaf528b14a437" + integrity sha512-ghRa5S8aH8z9I3WGbl4/ISqkNUOmiNLG1XWkN7SyCsd1UZmY0WZDiKMLU1ZQrPQQdrCPyC+jwpRkKwDdfFLVqw== + JSONStream@^1.0.3, JSONStream@^1.0.4: version "1.3.1" resolved "https://registry.yarnpkg.com/JSONStream/-/JSONStream-1.3.1.tgz#707f761e01dae9e16f1bcf93703b78c70966579a"