diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..21fc158 --- /dev/null +++ b/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - inquirer > lodash: + patched: '2020-05-01T02:46:38.202Z' + - sao > kopy > inquirer > lodash: + patched: '2020-05-01T02:46:38.202Z' diff --git a/package.json b/package.json index 2523a46..e76acfb 100644 --- a/package.json +++ b/package.json @@ -58,7 +58,9 @@ "prerelease.patch": "yarn run checkPackage", "prerelease.pre": "yarn run checkPackage", "clean": "rm -rf ./lib ./docs ./coverage ./.nyc_output", - "createLink": "yarn link --silent > /dev/null 2>&1 && yarn link --silent $npm_package_name" + "createLink": "yarn link --silent > /dev/null 2>&1 && yarn link --silent $npm_package_name", + "snyk-protect": "snyk protect", + "prepare": "yarn run snyk-protect" }, "config": { "commitizen": { @@ -74,7 +76,8 @@ "spdx-license-list": "^4.0.0", "superb": "^2.0.0", "tslib": "^1.9.0", - "validate-npm-package-name": "^3.0.0" + "validate-npm-package-name": "^3.0.0", + "snyk": "^1.316.1" }, "devDependencies": { "@commitlint/cli": "^6.1.3", @@ -112,5 +115,6 @@ "tslint": "^5.9.1", "typedoc": "^0.11.1", "typescript": "^2.8.1" - } + }, + "snyk": true }