diff --git a/javascript/.snyk b/javascript/.snyk new file mode 100644 index 0000000..c66e13e --- /dev/null +++ b/javascript/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.22.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - request-promise > request-promise-core > lodash: + patched: '2022-03-31T23:44:47.019Z' + - request-promise-native > request-promise-core > lodash: + patched: '2022-03-31T23:44:47.019Z' diff --git a/javascript/package-lock.json b/javascript/package-lock.json index c541adf..2cc331b 100644 --- a/javascript/package-lock.json +++ b/javascript/package-lock.json @@ -4,6 +4,11 @@ "lockfileVersion": 1, "requires": true, "dependencies": { + "@snyk/protect": { + "version": "1.893.0", + "resolved": "https://registry.npmjs.org/@snyk/protect/-/protect-1.893.0.tgz", + "integrity": "sha512-QHia0qAw3a+jGsAQzE87wVNclVtVy0kQAneloX1y1Ay/7Ks2wMAl1doNfr+MUrloxegoKJwiQU4msuKD/YwQjw==" + }, "ajv": { "version": "6.10.2", "resolved": "https://registry.npmjs.org/ajv/-/ajv-6.10.2.tgz", diff --git a/javascript/package.json b/javascript/package.json index a678b6a..87082fa 100644 --- a/javascript/package.json +++ b/javascript/package.json @@ -4,7 +4,9 @@ "description": "NiceHash Example App", "main": "index.js", "scripts": { - "test": "echo \"Error: no test specified\" && exit 1" + "test": "echo \"Error: no test specified\" && exit 1", + "prepare": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "author": "NiceHash", "license": "ISC", @@ -14,6 +16,8 @@ "qs": "^6.7.0", "request": "^2.88.0", "request-promise": "^4.2.4", - "request-promise-native": "^1.0.7" - } + "request-promise-native": "^1.0.7", + "@snyk/protect": "latest" + }, + "snyk": true }