diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..cdbc53e --- /dev/null +++ b/.snyk @@ -0,0 +1,51 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.19.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:debug:20170905': + - flashcore-node > socket.io-client > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > engine.io > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-adapter > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io-client > engine.io-client > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > engine.io-client > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io-client > socket.io-parser > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-parser > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-adapter > socket.io-parser > debug: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > socket.io-parser > debug: + patched: '2020-08-12T00:20:55.268Z' + 'npm:ms:20170412': + - flashcore-node > socket.io-client > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > engine.io > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-adapter > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io-client > engine.io-client > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > engine.io-client > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io-client > socket.io-parser > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-parser > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-adapter > socket.io-parser > debug > ms: + patched: '2020-08-12T00:20:55.268Z' + - flashcore-node > socket.io > socket.io-client > socket.io-parser > debug > ms: + patched: '2020-08-12T00:20:55.268Z' diff --git a/package.json b/package.json index 689510d..4557e5f 100644 --- a/package.json +++ b/package.json @@ -9,7 +9,9 @@ "main": "index.js", "scripts": { "test": "mocha test/** --recursive", - "build-deb": "./scripts/build-deb" + "build-deb": "./scripts/build-deb", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "bin": { "flashcore": "./bin/flashcore", @@ -96,6 +98,8 @@ "flashcore-lib": "flash-coin/flashcore-lib", "flashcore-node": "flash-coin/flashcore-node", "insight-flash-api": "flash-coin/insight-flash-api", - "insight-flash-ui": "flash-coin/insight-flash-ui" - } + "insight-flash-ui": "flash-coin/insight-flash-ui", + "snyk": "^1.373.0" + }, + "snyk": true }