From aa446a69b686400cab89e889921a4ed18ba46f2a Mon Sep 17 00:00:00 2001 From: snyk-test Date: Tue, 9 Jul 2019 03:39:33 +0000 Subject: [PATCH] fix: examples/nextjs/.snyk & examples/nextjs/package.json to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-450202 --- examples/nextjs/.snyk | 8 ++++++++ examples/nextjs/package.json | 10 +++++++--- 2 files changed, 15 insertions(+), 3 deletions(-) create mode 100644 examples/nextjs/.snyk diff --git a/examples/nextjs/.snyk b/examples/nextjs/.snyk new file mode 100644 index 00000000000000..82bef6e3c9085d --- /dev/null +++ b/examples/nextjs/.snyk @@ -0,0 +1,8 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.13.5 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-450202: + - next > next-server > styled-jsx > babel-types > lodash: + patched: '2019-07-09T03:39:30.932Z' diff --git a/examples/nextjs/package.json b/examples/nextjs/package.json index 35e067794607fb..32373f8966ce23 100644 --- a/examples/nextjs/package.json +++ b/examples/nextjs/package.json @@ -6,11 +6,15 @@ "material-ui": "next", "next": "latest", "react": "latest", - "react-dom": "latest" + "react-dom": "latest", + "snyk": "^1.192.4" }, "scripts": { "dev": "next", "build": "next build", - "start": "next start" - } + "start": "next start", + "snyk-protect": "snyk protect", + "prepublish": "npm run snyk-protect" + }, + "snyk": true }