From e8b6738ab06ed9bb59abfcaf43c32fa0e54f15fd Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 27 Apr 2023 05:42:25 +0000 Subject: [PATCH] fix: test/fixtures/qs-package/node_modules/is-retry-allowed/package.json & test/fixtures/qs-package/node_modules/is-retry-allowed/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 - https://snyk.io/vuln/SNYK-JS-DOTPROP-543489 - https://snyk.io/vuln/SNYK-JS-GOT-2932019 - https://snyk.io/vuln/SNYK-JS-JSYAML-173999 - https://snyk.io/vuln/SNYK-JS-JSYAML-174129 - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/SNYK-JS-LODASHMERGE-173732 - https://snyk.io/vuln/SNYK-JS-LODASHMERGE-173733 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-TRIMNEWLINES-1298042 - https://snyk.io/vuln/npm:eslint:20180222 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:minimatch:20160620 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:lodash:20180130 --- .../node_modules/is-retry-allowed/.snyk | 10 ++++++++++ .../node_modules/is-retry-allowed/package.json | 15 ++++++++++----- 2 files changed, 20 insertions(+), 5 deletions(-) create mode 100644 test/fixtures/qs-package/node_modules/is-retry-allowed/.snyk diff --git a/test/fixtures/qs-package/node_modules/is-retry-allowed/.snyk b/test/fixtures/qs-package/node_modules/is-retry-allowed/.snyk new file mode 100644 index 0000000000..ca5bb5a830 --- /dev/null +++ b/test/fixtures/qs-package/node_modules/is-retry-allowed/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:lodash:20180130': + - ava > babel-core > babel-plugin-proto-to-assign > lodash: + patched: '2023-04-27T05:42:21.473Z' + - xo > babel-eslint > babel-core > babel-plugin-proto-to-assign > lodash: + patched: '2023-04-27T05:42:21.473Z' diff --git a/test/fixtures/qs-package/node_modules/is-retry-allowed/package.json b/test/fixtures/qs-package/node_modules/is-retry-allowed/package.json index 3452ee1bbb..edef547b98 100644 --- a/test/fixtures/qs-package/node_modules/is-retry-allowed/package.json +++ b/test/fixtures/qs-package/node_modules/is-retry-allowed/package.json @@ -54,11 +54,13 @@ "bugs": { "url": "https://github.com/floatdrop/is-retry-allowed/issues" }, - "dependencies": {}, + "dependencies": { + "@snyk/protect": "latest" + }, "description": "My prime module", "devDependencies": { - "ava": "^0.8.0", - "xo": "^0.12.1" + "ava": "^4.0.0", + "xo": "^0.40.3" }, "directories": {}, "dist": { @@ -93,7 +95,10 @@ "url": "git+https://github.com/floatdrop/is-retry-allowed.git" }, "scripts": { - "test": "xo && ava" + "test": "xo && ava", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, - "version": "1.1.0" + "version": "1.1.0", + "snyk": true }