From 8639ba71df6a3933ac2d6abea9c88b55b5095d84 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 27 Apr 2023 17:05:21 +0000 Subject: [PATCH] fix: node_modules/ava/node_modules/source-map-support/package.json & node_modules/ava/node_modules/source-map-support/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ECSTATIC-540354 - https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905 - https://snyk.io/vuln/SNYK-JS-JSON5-3182856 - https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3042992 - https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3043105 - https://snyk.io/vuln/SNYK-JS-LOADERUTILS-3105943 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-MOCHA-2863123 - https://snyk.io/vuln/SNYK-JS-MOCHA-561476 - https://snyk.io/vuln/SNYK-JS-SHELLQUOTE-1766506 - https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251 - https://snyk.io/vuln/npm:braces:20180219 - https://snyk.io/vuln/npm:crypto-browserify:20140722 - https://snyk.io/vuln/npm:debug:20170905 - https://snyk.io/vuln/npm:diff:20180305 - https://snyk.io/vuln/npm:growl:20160721 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:shell-quote:20160621 - https://snyk.io/vuln/npm:uglify-js:20151024 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:uglify-js:20151024 --- .../ava/node_modules/source-map-support/.snyk | 8 ++++++++ .../source-map-support/package.json | 19 +++++++++++-------- 2 files changed, 19 insertions(+), 8 deletions(-) create mode 100644 node_modules/ava/node_modules/source-map-support/.snyk diff --git a/node_modules/ava/node_modules/source-map-support/.snyk b/node_modules/ava/node_modules/source-map-support/.snyk new file mode 100644 index 0000000000..334309ca47 --- /dev/null +++ b/node_modules/ava/node_modules/source-map-support/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:uglify-js:20151024': + - browserify > umd > ruglify > uglify-js: + patched: '2023-04-27T17:05:14.145Z' diff --git a/node_modules/ava/node_modules/source-map-support/package.json b/node_modules/ava/node_modules/source-map-support/package.json index f15f252838..98a54b2b4e 100644 --- a/node_modules/ava/node_modules/source-map-support/package.json +++ b/node_modules/ava/node_modules/source-map-support/package.json @@ -6,19 +6,21 @@ "scripts": { "build": "node build.js", "serve-tests": "http-server -p 1336", - "prepublish": "npm run build", - "test": "mocha" + "prepublish": "npm run snyk-protect && npm run build", + "test": "mocha", + "snyk-protect": "snyk-protect" }, "dependencies": { "buffer-from": "^1.0.0", - "source-map": "^0.6.0" + "source-map": "^0.6.0", + "@snyk/protect": "latest" }, "devDependencies": { - "browserify": "^4.2.3", + "browserify": "^12.0.0", "coffeescript": "^1.12.7", - "http-server": "^0.11.1", - "mocha": "^3.5.3", - "webpack": "^1.15.0" + "http-server": "^0.13.0", + "mocha": "^10.1.0", + "webpack": "^3.0.0" }, "repository": { "type": "git", @@ -27,5 +29,6 @@ "bugs": { "url": "https://github.com/evanw/node-source-map-support/issues" }, - "license": "MIT" + "license": "MIT", + "snyk": true } \ No newline at end of file