diff --git a/js/node/.snyk b/js/node/.snyk new file mode 100644 index 000000000000..df81cff1d901 --- /dev/null +++ b/js/node/.snyk @@ -0,0 +1,14 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.14.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - lodash: + patched: '2020-05-01T02:18:49.029Z' + - eslint > lodash: + patched: '2020-05-01T02:18:49.029Z' + - eslint > inquirer > lodash: + patched: '2020-05-01T02:18:49.029Z' + - eslint > table > lodash: + patched: '2020-05-01T02:18:49.029Z' diff --git a/js/node/package.json b/js/node/package.json index d3fada73ee4c..a0203cf16431 100644 --- a/js/node/package.json +++ b/js/node/package.json @@ -40,6 +40,12 @@ "type-is": "1.6.13", "underscore": "1.8.3", "vary": "1.1.0", - "xmldom": "0.1.27" - } + "xmldom": "0.1.27", + "snyk": "^1.316.1" + }, + "scripts": { + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" + }, + "snyk": true }