diff --git a/.snyk b/.snyk new file mode 100644 index 0000000..caec1c3 --- /dev/null +++ b/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:uglify-js:20151024': + - browserify > umd > ruglify > uglify-js: + patched: '2022-10-05T22:09:02.730Z' + - browserify > browser-pack > umd > ruglify > uglify-js: + patched: '2022-10-05T22:09:02.730Z' diff --git a/package.json b/package.json index d62af71..8c5cac2 100644 --- a/package.json +++ b/package.json @@ -5,7 +5,9 @@ "main": "index.js", "scripts": { "start": "node build.js", - "test": "echo \"Error: no test specified\" && exit 1" + "test": "echo \"Error: no test specified\" && exit 1", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "repository": { "type": "git", @@ -20,11 +22,13 @@ "dependencies": { "async": "^0.9.0", "auth-provider": "^0.6.2", - "browserify": "^8.1.3", - "ejs": "^2.2.4", + "browserify": "^12.0.0", + "ejs": "^3.1.7", "hellojs": "^1.4.3", - "highlight.js": "^8.4.0", + "highlight.js": "^9.18.2", "markdown": "^0.5.0", - "uglifyify": "^3.0.1" - } + "uglifyify": "^5.0.2", + "@snyk/protect": "latest" + }, + "snyk": true }