From df8ccb57df0e5a382832739c7bf788ef972d5596 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 27 May 2017 07:24:11 +0000 Subject: [PATCH] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:ms:20170412 Latest report for tnocs/csweb-sim: https://snyk.io/test/github/tnocs/csweb-sim --- .snyk | 27 ++++++++++++++++++++++++++- package.json | 2 +- 2 files changed, 27 insertions(+), 2 deletions(-) diff --git a/.snyk b/.snyk index 260973d..d7918c0 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.7.0 +version: v1.7.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -11,3 +11,28 @@ patch: patched: '2017-02-18T10:10:46.080Z' - csweb > hypertimer > ws: patched: '2017-02-18T10:10:46.080Z' + 'npm:ms:20170412': + - csweb > hypertimer > body-parser > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - hypertimer > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-parser > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-adapter > socket.io-parser > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-client > socket.io-parser > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - hypertimer > body-parser > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > hypertimer > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > engine.io > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-adapter > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-client > debug > ms: + patched: '2017-05-27T07:24:11.537Z' + - csweb > socket.io > socket.io-client > engine.io-client > debug > ms: + patched: '2017-05-27T07:24:11.537Z' diff --git a/package.json b/package.json index d57a086..e6b1323 100644 --- a/package.json +++ b/package.json @@ -28,7 +28,7 @@ "mosca": "^2.1.0", "setprototypeof": "^1.0.1", "winston": "^2.1.0", - "snyk": "^1.25.0" + "snyk": "^1.31.0" }, "devDependencies": { "chokidar": "^1.2.0",