diff --git a/.snyk b/.snyk index 19dad00..e889437 100644 --- a/.snyk +++ b/.snyk @@ -1,3 +1,8 @@ -version: v1.5.0 +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 ignore: {} -patch: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - inquirer > lodash: + patched: '2020-05-01T01:25:09.374Z' diff --git a/package.json b/package.json index ab36db6..cb63b61 100644 --- a/package.json +++ b/package.json @@ -4,7 +4,9 @@ "description": "A lightweight pattern library designed to be included with any web project.", "main": "./manager/astrum.js", "scripts": { - "test": "snyk test" + "test": "snyk test", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "repository": { "type": "git", @@ -32,9 +34,9 @@ "fs-extra": "^0.28.0", "inquirer": "^1.0.2", "is-windows": "^0.2.0", - "mkdirp": "^0.5.1" + "mkdirp": "^0.5.1", + "snyk": "^1.316.1" }, - "devDependencies": { - "snyk": "^1.14.3" - } + "devDependencies": {}, + "snyk": true }