diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..a6f2431 --- /dev/null +++ b/.snyk @@ -0,0 +1,14 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.5 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-450202: + - chimee-plugin-center-state > chimee-helper > toxic-predicate-functions > lodash: + patched: '2019-07-09T05:59:10.087Z' + - chimee-plugin-controlbar > chimee-helper > toxic-predicate-functions > lodash: + patched: '2019-07-09T05:59:10.087Z' + - chimee-plugin-center-state > chimee-helper > toxic-utils > lodash: + patched: '2019-07-09T05:59:10.087Z' + - chimee-plugin-controlbar > chimee-helper > toxic-utils > lodash: + patched: '2019-07-09T05:59:10.087Z' diff --git a/package.json b/package.json index e503ddc..0d19584 100644 --- a/package.json +++ b/package.json @@ -17,7 +17,9 @@ "b-es": "rollup -c build/rollup.config.es.js", "b-umd": "rollup -c build/rollup.config.umd.js", "b-esm": "rollup -c build/rollup.config.esm.js", - "b-min": "rollup -c build/rollup.config.min.js" + "b-min": "rollup -c build/rollup.config.min.js", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "repository": { "type": "git", @@ -47,7 +49,8 @@ "chimee-plugin-contextmenu": "^0.1.2", "chimee-plugin-controlbar": "^0.5.0", "chimee-plugin-log": "0.0.4", - "chimee-plugin-popup": "0.0.7" + "chimee-plugin-popup": "0.0.7", + "snyk": "^1.192.4" }, "devDependencies": { "@babel/core": "^7.1.5", @@ -151,5 +154,6 @@ "deletions": 39, "hireable": null } - ] + ], + "snyk": true }