diff --git a/.snyk b/.snyk index ea661d3..0e1e8b2 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.13.5 +version: v1.14.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -12,3 +12,12 @@ patch: patched: '2019-07-03T23:21:28.755Z' - apollo-server-express > apollo-server-core > apollo-engine-reporting > lodash: patched: '2019-07-03T23:21:28.755Z' + SNYK-JS-LODASH-567746: + - lodash: + patched: '2020-04-30T22:52:05.914Z' + - apollo-server-express > apollo-server-core > lodash: + patched: '2020-04-30T22:52:05.914Z' + - request-promise > request-promise-core > lodash: + patched: '2020-04-30T22:52:05.914Z' + - apollo-server-express > apollo-server-core > apollo-engine-reporting > lodash: + patched: '2020-04-30T22:52:05.914Z' diff --git a/package.json b/package.json index d88956e..c447fed 100644 --- a/package.json +++ b/package.json @@ -7,7 +7,7 @@ "start": "nodemon ./src/server.js --exec babel-node", "test": "echo \"Error: no test specified\" && exit 1", "snyk-protect": "snyk protect", - "prepublish": "npm run snyk-protect" + "prepublish": "yarn run snyk-protect" }, "author": "", "devDependencies": { @@ -29,7 +29,7 @@ "lodash": "^4.17.4", "request": "^2.88.0", "request-promise": "^4.2.2", - "snyk": "^1.189.0" + "snyk": "^1.316.1" }, "snyk": true }