From d4532a5064c7fd3e052348d245fb2c3a19e3a5c9 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 8 Jul 2023 03:07:02 +0000 Subject: [PATCH] fix: deps/npm/node_modules/process/package.json & deps/npm/node_modules/process/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388 - https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818 - https://snyk.io/vuln/SNYK-JS-MINIMIST-2429795 - https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 - https://snyk.io/vuln/SNYK-JS-MOCHA-2863123 - https://snyk.io/vuln/SNYK-JS-MOCHA-561476 - https://snyk.io/vuln/npm:debug:20170905 - https://snyk.io/vuln/npm:growl:20160721 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:ms:20151024 - https://snyk.io/vuln/npm:ms:20170412 The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/npm:debug:20170905 - https://snyk.io/vuln/npm:hawk:20160119 - https://snyk.io/vuln/npm:http-signature:20150122 - https://snyk.io/vuln/npm:lodash:20180130 - https://snyk.io/vuln/npm:mime:20170907 - https://snyk.io/vuln/npm:minimatch:20160620 - https://snyk.io/vuln/npm:ms:20151024 - https://snyk.io/vuln/npm:ms:20170412 - https://snyk.io/vuln/npm:negotiator:20160616 - https://snyk.io/vuln/npm:qs:20140806-1 - https://snyk.io/vuln/npm:request:20160119 - https://snyk.io/vuln/npm:tunnel-agent:20170305 - https://snyk.io/vuln/npm:uglify-js:20151024 --- deps/npm/node_modules/process/.snyk | 144 +++++++++++++++++++++ deps/npm/node_modules/process/package.json | 10 +- 2 files changed, 152 insertions(+), 2 deletions(-) create mode 100644 deps/npm/node_modules/process/.snyk diff --git a/deps/npm/node_modules/process/.snyk b/deps/npm/node_modules/process/.snyk new file mode 100644 index 00000000000000..f73c593c9cda0e --- /dev/null +++ b/deps/npm/node_modules/process/.snyk @@ -0,0 +1,144 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + 'npm:debug:20170905': + - zuul > compression > debug: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:debug:20170905' + path: zuul > compression > debug + - zuul > istanbul-middleware > body-parser > debug: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:debug:20170905' + path: zuul > istanbul-middleware > body-parser > debug + - zuul > debug: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:debug:20170905' + path: zuul > debug + 'npm:hawk:20160119': + - zuul > wd > request > hawk: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:hawk:20160119' + path: zuul > wd > request > hawk + 'npm:http-signature:20150122': + - zuul > wd > request > http-signature: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:http-signature:20150122' + path: zuul > wd > request > http-signature + 'npm:lodash:20180130': + - zuul > lodash: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:lodash:20180130' + path: zuul > lodash + 'npm:mime:20170907': + - zuul > express > send > mime: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:mime:20170907' + path: zuul > express > send > mime + - zuul > express > connect > send > mime: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:mime:20170907' + path: zuul > express > connect > send > mime + - zuul > wd > request > form-data > mime: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:mime:20170907' + path: zuul > wd > request > form-data > mime + - zuul > zuul-localtunnel > localtunnel > request > mime: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:mime:20170907' + path: zuul > zuul-localtunnel > localtunnel > request > mime + - zuul > zuul-localtunnel > localtunnel > request > form-data > mime: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:mime:20170907' + path: zuul > zuul-localtunnel > localtunnel > request > form-data > mime + 'npm:minimatch:20160620': + - zuul > browserify-istanbul > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > browserify-istanbul > minimatch + - zuul > firefox-profile > archiver > file-utils > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > firefox-profile > archiver > file-utils > minimatch + - zuul > browserify-istanbul > istanbul > fileset > glob > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > browserify-istanbul > istanbul > fileset > glob > minimatch + - zuul > firefox-profile > archiver > file-utils > glob > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > firefox-profile > archiver > file-utils > glob > minimatch + - zuul > firefox-profile > archiver > file-utils > findup-sync > glob > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: >- + zuul > firefox-profile > archiver > file-utils > findup-sync > glob > + minimatch + - zuul > browserify-istanbul > istanbul > fileset > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > browserify-istanbul > istanbul > fileset > minimatch + - zuul > istanbul-middleware > archiver > glob > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > istanbul-middleware > archiver > glob > minimatch + - zuul > wd > archiver > glob > minimatch: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:minimatch:20160620' + path: zuul > wd > archiver > glob > minimatch + 'npm:ms:20170412': + - zuul > compression > debug > ms: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:ms:20170412' + path: zuul > compression > debug > ms + - zuul > istanbul-middleware > body-parser > debug > ms: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:ms:20170412' + path: zuul > istanbul-middleware > body-parser > debug > ms + 'npm:ms:20151024': + - zuul > debug > ms: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:ms:20151024' + path: zuul > debug > ms + 'npm:negotiator:20160616': + - zuul > compression > accepts > negotiator: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:negotiator:20160616' + path: zuul > compression > accepts > negotiator + - zuul > express > connect > negotiator: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:negotiator:20160616' + path: zuul > express > connect > negotiator + 'npm:qs:20140806-1': + - zuul > express > connect > qs: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:qs:20140806-1' + path: zuul > express > connect > qs + - zuul > superagent > qs: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:qs:20140806-1' + path: zuul > superagent > qs + 'npm:request:20160119': + - zuul > wd > request: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:request:20160119' + path: zuul > wd > request + - zuul > zuul-localtunnel > localtunnel > request: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:request:20160119' + path: zuul > zuul-localtunnel > localtunnel > request + 'npm:tunnel-agent:20170305': + - zuul > wd > request > tunnel-agent: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:tunnel-agent:20170305' + path: zuul > wd > request > tunnel-agent + 'npm:uglify-js:20151024': + - zuul > hbs > handlebars > uglify-js: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:uglify-js:20151024' + path: zuul > hbs > handlebars > uglify-js + - zuul > browserify-istanbul > istanbul > handlebars > uglify-js: + patched: '2023-07-08T03:06:59.993Z' + id: 'npm:uglify-js:20151024' + path: zuul > browserify-istanbul > istanbul > handlebars > uglify-js diff --git a/deps/npm/node_modules/process/package.json b/deps/npm/node_modules/process/package.json index d2cfaade44177a..5b17a897da7462 100644 --- a/deps/npm/node_modules/process/package.json +++ b/deps/npm/node_modules/process/package.json @@ -7,7 +7,9 @@ ], "scripts": { "test": "mocha test.js", - "browser": "zuul --no-coverage --ui mocha-bdd --local 8080 -- test.js" + "browser": "zuul --no-coverage --ui mocha-bdd --local 8080 -- test.js", + "prepublish": "npm run snyk-protect", + "snyk-protect": "snyk-protect" }, "version": "0.11.10", "repository": { @@ -21,7 +23,11 @@ "node": ">= 0.6.0" }, "devDependencies": { - "mocha": "2.2.1", + "mocha": "10.1.0", "zuul": "^3.10.3" + }, + "snyk": true, + "dependencies": { + "@snyk/protect": "latest" } }