diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..ce08b75 --- /dev/null +++ b/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.5 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-450202: + - strong-soap > lodash: + patched: '2019-07-03T21:42:28.804Z' + - strong-soap > strong-globalize > lodash: + patched: '2019-07-03T21:42:28.804Z' diff --git a/package.json b/package.json index 739f225..61e4b85 100644 --- a/package.json +++ b/package.json @@ -10,7 +10,9 @@ "codeclimate": "codeclimate-test-reporter < coverage/lcov.info", "release:major": "changelog -M && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version major && git push origin && git push origin --tags && npm publish", "release:minor": "changelog -m && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version minor && git push origin && git push origin --tags && npm publish", - "release:patch": "changelog -p && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version patch && git push origin && git push origin --tags && npm publish" + "release:patch": "changelog -p && git add CHANGELOG.md && git commit -m 'updated CHANGELOG.md' && npm version patch && git push origin && git push origin --tags && npm publish", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "engines": { "node": ">=4" @@ -35,7 +37,8 @@ "moment": "^2.14.1", "node-forge": "^0.8.0", "strong-soap": "^1.1.0", - "xml-c14n": "^0.0.6" + "xml-c14n": "^0.0.6", + "snyk": "^1.189.0" }, "devDependencies": { "chai": "4.2.0", @@ -72,5 +75,6 @@ "always" ] } - } + }, + "snyk": true }