diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..9204683 --- /dev/null +++ b/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - chimee-plugin-controlbar > chimee-helper > toxic-predicate-functions > lodash: + patched: '2020-05-05T05:57:07.299Z' + - chimee-plugin-controlbar > chimee-helper > toxic-utils > lodash: + patched: '2020-05-05T05:57:07.299Z' diff --git a/package.json b/package.json index c26d01e..6a45c3f 100644 --- a/package.json +++ b/package.json @@ -17,7 +17,9 @@ "b-es": "rollup -c build/rollup.config.es.js", "b-umd": "rollup -c build/rollup.config.umd.js", "b-esm": "rollup -c build/rollup.config.esm.js", - "b-min": "rollup -c build/rollup.config.min.js" + "b-min": "rollup -c build/rollup.config.min.js", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "repository": { "type": "git", @@ -47,7 +49,8 @@ "chimee-plugin-contextmenu": "^0.1.2", "chimee-plugin-controlbar": "^0.5.0", "chimee-plugin-log": "0.0.4", - "chimee-plugin-popup": "0.0.8" + "chimee-plugin-popup": "0.0.8", + "snyk": "^1.317.0" }, "devDependencies": { "@babel/core": "^7.1.5", @@ -151,5 +154,6 @@ "deletions": 39, "hireable": null } - ] + ], + "snyk": true }