From fc4c7a610af496d3a4f489e89481b48963e54a6e Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 3 May 2020 02:29:16 -0500 Subject: [PATCH 1/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/package.json b/package.json index 86d81b5..b2d84d4 100644 --- a/package.json +++ b/package.json @@ -21,7 +21,7 @@ "dependencies": { "log-timestamp": "^0.1.2", "pm2": "^2.4.0", - "snyk": "^1.192.3" + "snyk": "^1.316.2" }, "scripts": { "snyk-protect": "snyk protect", From 112dc8d8fe13ac09224b3448b803e4e1b40c24ac Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sun, 3 May 2020 02:29:17 -0500 Subject: [PATCH 2/2] fix: package.json & .snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- .snyk | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/.snyk b/.snyk index 468ff37..95766b8 100644 --- a/.snyk +++ b/.snyk @@ -1,5 +1,5 @@ # Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. -version: v1.13.5 +version: v1.14.1 ignore: {} # patches apply the minimum changes required to fix a vulnerability patch: @@ -8,3 +8,8 @@ patch: patched: '2019-07-07T07:28:51.570Z' - pm2 > pm2-deploy > async > lodash: patched: '2019-07-07T07:28:51.570Z' + SNYK-JS-LODASH-567746: + - pm2 > async > lodash: + patched: '2020-05-03T07:28:50.493Z' + - pm2 > pm2-deploy > async > lodash: + patched: '2020-05-03T07:28:50.493Z'