From 300d219923b9a5a09b58d912911b79a8dcbb97a8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 25 Oct 2018 06:43:14 +0000 Subject: [PATCH] fix: .snyk & package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:minimatch:20160620 --- .snyk | 14 +++++++++++++- package.json | 5 +++-- 2 files changed, 16 insertions(+), 3 deletions(-) diff --git a/.snyk b/.snyk index 18fa503..863a912 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.7.1 +version: v1.12.0 # ignores vulnerabilities until expiry date; change duration by modifying expiry date ignore: 'npm:shell-quote:20160621': @@ -21,6 +21,18 @@ patch: patched: '2016-09-01T19:17:18.824Z' - laravel-elixir > gulp-phpunit > gulp > vinyl-fs > glob-watcher > gaze > globule > glob > minimatch: patched: '2016-09-01T19:17:18.824Z' + - gulp-jscs > jscs > babel-jscs > babel-core > minimatch: + patched: '2018-10-25T06:43:12.646Z' + - laravel-elixir > browserify > glob > minimatch: + patched: '2018-10-25T06:43:12.646Z' + - laravel-elixir > gulp-phpunit > gulp > vinyl-fs > glob-stream > minimatch: + patched: '2018-10-25T06:43:12.646Z' + - laravel-elixir > gulp-if > gulp-match > minimatch: + patched: '2018-10-25T06:43:12.646Z' + - laravel-elixir > gulp-phpunit > gulp > vinyl-fs > glob-watcher > gaze > globule > minimatch: + patched: '2018-10-25T06:43:12.646Z' + - laravel-elixir > gulp-phpunit > gulp > vinyl-fs > glob-watcher > gaze > globule > glob > minimatch: + patched: '2018-10-25T06:43:12.646Z' 'npm:ms:20170412': - laravel-elixir > browser-sync > serve-static > send > ms: patched: '2017-05-25T03:56:22.137Z' diff --git a/package.json b/package.json index 91885cf..2b9b60a 100644 --- a/package.json +++ b/package.json @@ -7,13 +7,14 @@ "gulp-jscs": "2.0.0", "laravel-elixir": "4.0.1", "gulp-notify": "^2.2.0", - "snyk": "^1.30.1" + "snyk": "^1.105.0" }, "devDependencies": {}, "scripts": { "test": "echo \"Error: no test specified\" && exit 1", "snyk-protect": "snyk protect", - "prepublish": "npm run snyk-protect" + "prepublish": "npm run snyk-protect", + "prepare": "npm run snyk-protect" }, "repository": { "type": "git",