diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..eec5653 --- /dev/null +++ b/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.15.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - ava > concordance > lodash: + patched: '2020-06-14T21:38:53.223Z' diff --git a/package.json b/package.json index c8465b3..b070dff 100644 --- a/package.json +++ b/package.json @@ -11,7 +11,9 @@ "test": "cross-env psp && nyc --reporter=lcov ava --verbose", "doc": "jsdoc -c ./jsdoc.json -r -R ./README.md -P ./package.json --verbose", "coverage": "codecov", - "report": "nyc report --reporter=html" + "report": "nyc report --reporter=html", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "husky": { "hooks": { @@ -75,6 +77,8 @@ "@slimio/scheduler": "^0.8.0", "@slimio/timer": "^1.0.2", "is-snake-case": "^0.1.0", - "zen-observable": "^0.8.15" - } + "zen-observable": "^0.8.15", + "snyk": "^1.339.3" + }, + "snyk": true }