From 3d356578c7281b37761e6218ba0e37669dbb7bff Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Thu, 27 Apr 2023 20:51:11 +0000 Subject: [PATCH] fix: test/fixtures/qs-package/node_modules/cli-width/package.json & test/fixtures/qs-package/node_modules/cli-width/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-HAWK-2808852 - https://snyk.io/vuln/SNYK-JS-JSYAML-173999 - https://snyk.io/vuln/SNYK-JS-JSYAML-174129 - https://snyk.io/vuln/SNYK-JS-LODASH-1018905 - https://snyk.io/vuln/SNYK-JS-LODASH-1040724 - https://snyk.io/vuln/SNYK-JS-LODASH-450202 - https://snyk.io/vuln/SNYK-JS-LODASH-567746 - https://snyk.io/vuln/SNYK-JS-LODASH-608086 - https://snyk.io/vuln/SNYK-JS-LODASH-73638 - https://snyk.io/vuln/SNYK-JS-LODASH-73639 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/npm:hoek:20180212 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:tunnel-agent:20170305 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:lodash:20180130 --- .../qs-package/node_modules/cli-width/.snyk | 8 ++++++++ .../node_modules/cli-width/package.json | 19 ++++++++++++------- 2 files changed, 20 insertions(+), 7 deletions(-) create mode 100644 test/fixtures/qs-package/node_modules/cli-width/.snyk diff --git a/test/fixtures/qs-package/node_modules/cli-width/.snyk b/test/fixtures/qs-package/node_modules/cli-width/.snyk new file mode 100644 index 0000000000..bd6c3d748f --- /dev/null +++ b/test/fixtures/qs-package/node_modules/cli-width/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.0 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:lodash:20180130': + - isparta > babel-core > babel-plugin-proto-to-assign > lodash: + patched: '2023-04-27T20:51:06.417Z' diff --git a/test/fixtures/qs-package/node_modules/cli-width/package.json b/test/fixtures/qs-package/node_modules/cli-width/package.json index d6802c86fe..513151b6bc 100644 --- a/test/fixtures/qs-package/node_modules/cli-width/package.json +++ b/test/fixtures/qs-package/node_modules/cli-width/package.json @@ -53,14 +53,16 @@ "bugs": { "url": "https://github.com/knownasilya/cli-width/issues" }, - "dependencies": {}, + "dependencies": { + "@snyk/protect": "latest" + }, "description": "Get stdout window width, with two fallbacks, tty and then a default.", "devDependencies": { - "coveralls": "^2.11.4", - "isparta": "^3.0.4", + "coveralls": "^3.0.0", + "isparta": "^4.0.0", "rimraf": "^2.4.3", - "tap-spec": "^4.1.0", - "tape": "^3.4.0" + "tap-spec": "^5.0.0", + "tape": "^4.0.0" }, "directories": {}, "dist": { @@ -88,7 +90,10 @@ "coverage": "isparta cover test/*.js | tspec", "coveralls": "npm run coverage -s && coveralls < coverage/lcov.info", "postcoveralls": "rimraf ./coverage", - "test": "node test | tspec" + "test": "node test | tspec", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, - "version": "2.1.0" + "version": "2.1.0", + "snyk": true }