From ad26bdba70ce84cf68d2135c658c73c53d025814 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Fri, 28 Apr 2023 15:45:27 +0000 Subject: [PATCH] fix: test/fixtures/qs-package/node_modules/write-file-atomic/package.json & test/fixtures/qs-package/node_modules/write-file-atomic/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 - https://snyk.io/vuln/SNYK-JS-HAWK-2808852 - https://snyk.io/vuln/SNYK-JS-JSYAML-173999 - https://snyk.io/vuln/SNYK-JS-JSYAML-174129 - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/npm:hoek:20180212 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:tunnel-agent:20170305 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:hawk:20160119 - https://snyk.io/vuln/npm:http-signature:20150122 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:mime:20170907 - https://snyk.io/vuln/npm:request:20160119 - https://snyk.io/vuln/npm:tunnel-agent:20170305 --- .../node_modules/write-file-atomic/.snyk | 25 +++++++++++++++++++ .../write-file-atomic/package.json | 14 +++++++---- 2 files changed, 34 insertions(+), 5 deletions(-) create mode 100644 test/fixtures/qs-package/node_modules/write-file-atomic/.snyk diff --git a/test/fixtures/qs-package/node_modules/write-file-atomic/.snyk b/test/fixtures/qs-package/node_modules/write-file-atomic/.snyk new file mode 100644 index 0000000000..d2dccfff35 --- /dev/null +++ b/test/fixtures/qs-package/node_modules/write-file-atomic/.snyk @@ -0,0 +1,25 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:hawk:20160119': + - tap > codecov.io > request > hawk: + patched: '2023-04-28T15:45:23.684Z' + 'npm:http-signature:20150122': + - tap > codecov.io > request > http-signature: + patched: '2023-04-28T15:45:23.684Z' + 'npm:lodash:20180130': + - standard > standard-engine > eslint > inquirer > lodash: + patched: '2023-04-28T15:45:23.684Z' + - standard > standard-format > esformatter-jsx > babel-core > babel-plugin-proto-to-assign > lodash: + patched: '2023-04-28T15:45:23.684Z' + 'npm:mime:20170907': + - tap > codecov.io > request > form-data > mime: + patched: '2023-04-28T15:45:23.684Z' + 'npm:request:20160119': + - tap > codecov.io > request: + patched: '2023-04-28T15:45:23.684Z' + 'npm:tunnel-agent:20170305': + - tap > codecov.io > request > tunnel-agent: + patched: '2023-04-28T15:45:23.684Z' diff --git a/test/fixtures/qs-package/node_modules/write-file-atomic/package.json b/test/fixtures/qs-package/node_modules/write-file-atomic/package.json index 3d9b36f9ab..cbb014505e 100644 --- a/test/fixtures/qs-package/node_modules/write-file-atomic/package.json +++ b/test/fixtures/qs-package/node_modules/write-file-atomic/package.json @@ -54,13 +54,14 @@ "dependencies": { "graceful-fs": "^4.1.2", "imurmurhash": "^0.1.4", - "slide": "^1.1.5" + "slide": "^1.1.5", + "@snyk/protect": "latest" }, "description": "Write files in an atomic fashion w/configurable ownership", "devDependencies": { "require-inject": "^1.1.0", - "standard": "^5.4.1", - "tap": "^2.3.1" + "standard": "^6.0.0", + "tap": "^14.6.8" }, "directories": {}, "dist": { @@ -93,7 +94,10 @@ "url": "git+ssh://git@github.com/iarna/write-file-atomic.git" }, "scripts": { - "test": "standard && tap --coverage test/*.js" + "test": "standard && tap --coverage test/*.js", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, - "version": "1.1.4" + "version": "1.1.4", + "snyk": true }