diff --git a/packages/composer-cli/.snyk b/packages/composer-cli/.snyk new file mode 100644 index 0000000000..3df08b1e81 --- /dev/null +++ b/packages/composer-cli/.snyk @@ -0,0 +1,38 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.3 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-AXIOS-174505: + - composer-client > composer-wallet-inmemory > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-client > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-admin > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-wallet-filesystem > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-wallet-inmemory > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-admin > composer-wallet-inmemory > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-client > composer-wallet-filesystem > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-admin > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-admin > composer-wallet-filesystem > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-client > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-client > composer-wallet-filesystem > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-client > composer-wallet-inmemory > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-admin > composer-wallet-filesystem > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' + - composer-documentation > composer-admin > composer-wallet-inmemory > composer-common > axios: + patched: '2019-05-05T23:30:55.064Z' diff --git a/packages/composer-cli/package.json b/packages/composer-cli/package.json index 1bbd356145..38f14103e5 100644 --- a/packages/composer-cli/package.json +++ b/packages/composer-cli/package.json @@ -17,7 +17,9 @@ "licchk": "license-check-and-add", "test": "nyc mocha --recursive -t 10000", "mocha": "mocha --recursive -t 10000", - "nyc": "nyc mocha --recursive -t 10000" + "nyc": "nyc mocha --recursive -t 10000", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" }, "repository": { "type": "git", @@ -63,7 +65,8 @@ "sanitize-filename": "1.6.1", "tar": "4.3.0", "valid-url": "1.0.9", - "yargs": "10.0.3" + "yargs": "10.0.3", + "snyk": "^1.161.1" }, "license-check-and-add-config": { "folder": ".", @@ -125,5 +128,6 @@ "branches": 100, "functions": 100, "lines": 100 - } + }, + "snyk": true }