diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..000ef29 --- /dev/null +++ b/.snyk @@ -0,0 +1,40 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - lerna > @lerna/publish > @lerna/version > @lerna/conventional-commits > conventional-changelog-core > lodash: + patched: '2023-05-24T20:50:06.361Z' + - '@babel/preset-env > @babel/plugin-proposal-async-generator-functions > @babel/helper-remap-async-to-generator > @babel/helper-wrap-function > @babel/traverse > @babel/generator > lodash': + patched: '2023-05-24T20:50:06.361Z' + - lerna > @lerna/publish > @lerna/version > @lerna/conventional-commits > conventional-changelog-core > conventional-changelog-writer > lodash: + patched: '2023-05-24T20:50:06.361Z' + - lerna > @lerna/publish > @lerna/version > @lerna/conventional-commits > conventional-changelog-core > conventional-commits-parser > lodash: + patched: '2023-05-24T20:50:06.361Z' + - lerna > @lerna/publish > @lerna/version > @lerna/conventional-commits > conventional-recommended-bump > conventional-commits-parser > lodash: + patched: '2023-05-24T20:50:06.361Z' + - '@babel/preset-env > @babel/plugin-proposal-async-generator-functions > @babel/helper-remap-async-to-generator > @babel/helper-wrap-function > @babel/helper-function-name > @babel/helper-get-function-arity > @babel/types > lodash': + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > @babel/core > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > jest-runtime > jest-config > @jest/test-sequencer > jest-runner > jest-jasmine2 > @babel/traverse > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > jest-runtime > jest-config > jest-environment-jsdom > jsdom > request-promise-native > request-promise-core > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > @babel/core > @babel/generator > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > jest-runtime > jest-config > @jest/test-sequencer > jest-runner > jest-jasmine2 > @babel/traverse > @babel/generator > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > babel-plugin-istanbul > istanbul-lib-instrument > @babel/core > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > @babel/core > @babel/generator > @babel/types > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > babel-plugin-istanbul > istanbul-lib-instrument > @babel/core > @babel/generator > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > babel-plugin-istanbul > istanbul-lib-instrument > @babel/core > @babel/helpers > @babel/traverse > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > babel-plugin-istanbul > istanbul-lib-instrument > @babel/core > @babel/helpers > @babel/traverse > @babel/generator > lodash: + patched: '2023-05-24T20:50:06.361Z' + - jest > @jest/core > @jest/reporters > @jest/environment > @jest/fake-timers > jest-message-util > @jest/test-result > @jest/transform > @babel/core > @babel/helpers > @babel/traverse > @babel/helper-function-name > @babel/helper-get-function-arity > @babel/types > lodash: + patched: '2023-05-24T20:50:06.361Z' diff --git a/package.json b/package.json index dae7e33..de77d5c 100644 --- a/package.json +++ b/package.json @@ -37,13 +37,13 @@ "eslint-plugin-import": "2.20.0", "eslint-plugin-react": "7.18.3", "eslint-plugin-react-hooks": "2.5.0", - "husky": "4.2.3", + "husky": "4.3.7", "invariant": "2.2.4", "jest": "25.1.0", - "lerna": "3.20.2", + "lerna": "5.5.2", "lint-staged": "10.0.8", "prettier": "1.19.1", - "ramda": "0.27.0", + "ramda": "0.27.2", "ramda-extension": "0.10.2", "react": "16.13.0", "react-dom": "16.13.0", @@ -56,17 +56,22 @@ "rollup-plugin-commonjs": "10.1.0", "rollup-plugin-node-resolve": "5.2.0", "rollup-plugin-replace": "2.2.0", - "rollup-plugin-terser": "5.2.0", + "rollup-plugin-terser": "5.3.1", "rxjs": "6.5.4", "rxjs-marbles": "5.0.4", - "serve": "11.3.0" + "serve": "14.1.0" }, "scripts": { "test": "jest", "lint": "yarn lint:eslint", "lint:eslint": "eslint --ext .js ./", "build": "lerna exec -- rollup -c=../../rollup.config.js", - "prepublish": "yarn build", - "docs": "serve docs" + "prepublish": "yarn run snyk-protect && yarn build", + "docs": "serve docs", + "snyk-protect": "snyk-protect" + }, + "snyk": true, + "dependencies": { + "@snyk/protect": "latest" } }