From 95b3d4e32633c99a4dcfd63bedd98bf7b5bab0e4 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 28 Oct 2023 16:57:17 +0000 Subject: [PATCH] fix: test/acceptance/workspaces/yarn-workspaces/package.json & test/acceptance/workspaces/yarn-workspaces/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- test/acceptance/workspaces/yarn-workspaces/.snyk | 10 ++++++++-- .../acceptance/workspaces/yarn-workspaces/package.json | 10 ++++++++-- 2 files changed, 16 insertions(+), 4 deletions(-) diff --git a/test/acceptance/workspaces/yarn-workspaces/.snyk b/test/acceptance/workspaces/yarn-workspaces/.snyk index 8d9d21960e..dd9d218a6e 100644 --- a/test/acceptance/workspaces/yarn-workspaces/.snyk +++ b/test/acceptance/workspaces/yarn-workspaces/.snyk @@ -1,9 +1,15 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.14.1 +version: v1.25.1 # ignores vulnerabilities until expiry date; change duration by modifying expiry date ignore: 'npm:node-uuid:20111130': - '*': reason: None Given expires: 2020-07-17T21:40:21.917Z -patch: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - wsrun > lodash: + patched: '2023-10-28T16:57:15.973Z' + id: SNYK-JS-LODASH-567746 + path: wsrun > lodash diff --git a/test/acceptance/workspaces/yarn-workspaces/package.json b/test/acceptance/workspaces/yarn-workspaces/package.json index 7bbc705989..c117dfd1c2 100644 --- a/test/acceptance/workspaces/yarn-workspaces/package.json +++ b/test/acceptance/workspaces/yarn-workspaces/package.json @@ -15,6 +15,12 @@ "wsrun": "^3.6.2" }, "dependencies": { - "node-fetch": "^2.3.0" - } + "node-fetch": "^2.3.0", + "@snyk/protect": "latest" + }, + "scripts": { + "prepare": "yarn run snyk-protect", + "snyk-protect": "snyk-protect" + }, + "snyk": true }