diff --git a/.snyk b/.snyk index f46e4d1e5b..74e604e8b9 100644 --- a/.snyk +++ b/.snyk @@ -1,8 +1,11 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.7.1 +version: v1.25.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: 'npm:marked:20170112': - marked: patched: '2017-05-24T23:11:38.941Z' + 'npm:request:20160119': + - tap > codecov.io > request: + patched: '2023-06-21T14:02:14.483Z' diff --git a/package.json b/package.json index 770b74a2a1..ed35e569f9 100644 --- a/package.json +++ b/package.json @@ -11,31 +11,31 @@ "start": "node app.js", "build": "browserify -r jquery > public/js/bundle.js", "cleanup": "mongo express-todo --eval 'db.todos.remove({});'", - "snyk-protect": "snyk protect", + "snyk-protect": "snyk-protect", "prepublish": "npm run snyk-protect" }, "dependencies": { - "body-parser": "1.9.0", + "body-parser": "1.19.2", "cookie-parser": "1.3.3", "ejs": "1.0.0", "ejs-locals": "1.0.2", "errorhandler": "1.2.0", - "express": "4.12.4", + "express": "4.17.3", "express-fileupload": "0.0.5", "humanize-ms": "1.0.1", "jquery": "^2.2.4", "marked": "0.3.5", "method-override": "latest", "moment": "2.15.1", - "mongoose": "4.2.4", + "mongoose": "5.12.3", "morgan": "latest", "ms": "^0.7.1", "npmconf": "0.0.24", "optional": "^0.1.3", "st": "0.2.4", "stream-buffers": "^3.0.1", - "tap": "^5.7.0", - "snyk": "^1.30.1" + "tap": "^15.0.0", + "@snyk/protect": "latest" }, "devDependencies": { "browserify": "^13.1.1"