From 2a0deaed1ce2d72c2f08021b8451ec47e7b50052 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Sat, 15 Jun 2024 22:36:34 +0000 Subject: [PATCH] fix: standalone-packages/monaco-editor/package.json, standalone-packages/monaco-editor/yarn.lock & standalone-packages/monaco-editor/.snyk to reduce vulnerabilities The following vulnerabilities are fixed with a Snyk patch: - https://snyk.io/vuln/SNYK-JS-LODASH-567746 --- standalone-packages/monaco-editor/.snyk | 10 ++++++++++ standalone-packages/monaco-editor/package.json | 9 +++++++-- standalone-packages/monaco-editor/yarn.lock | 5 +++++ 3 files changed, 22 insertions(+), 2 deletions(-) create mode 100644 standalone-packages/monaco-editor/.snyk diff --git a/standalone-packages/monaco-editor/.snyk b/standalone-packages/monaco-editor/.snyk new file mode 100644 index 00000000000..40a8b933ddd --- /dev/null +++ b/standalone-packages/monaco-editor/.snyk @@ -0,0 +1,10 @@ +# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities. +version: v1.25.1 +ignore: {} +# patches apply the minimum changes required to fix a vulnerability +patch: + SNYK-JS-LODASH-567746: + - typedoc > lodash: + patched: '2024-06-15T22:36:04.327Z' + id: SNYK-JS-LODASH-567746 + path: typedoc > lodash diff --git a/standalone-packages/monaco-editor/package.json b/standalone-packages/monaco-editor/package.json index 4ff733b2a07..02a43b51edb 100644 --- a/standalone-packages/monaco-editor/package.json +++ b/standalone-packages/monaco-editor/package.json @@ -8,7 +8,9 @@ "scripts": { "simpleserver": "gulp simpleserver", "release": "gulp release", - "website": "gulp website" + "website": "gulp website", + "prepare": "yarn run snyk-protect", + "snyk-protect": "snyk-protect" }, "typings": "./esm/vs/editor/editor.api.d.ts", "module": "./esm/vs/editor/editor.main.js", @@ -33,5 +35,8 @@ "uncss": "^0.16.2", "vinyl": "^0.5.3" }, - "dependencies": {} + "dependencies": { + "@snyk/protect": "latest" + }, + "snyk": true } diff --git a/standalone-packages/monaco-editor/yarn.lock b/standalone-packages/monaco-editor/yarn.lock index 97f584884de..b6448be3924 100644 --- a/standalone-packages/monaco-editor/yarn.lock +++ b/standalone-packages/monaco-editor/yarn.lock @@ -2,6 +2,11 @@ # yarn lockfile v1 +"@snyk/protect@^1.1291.1": + version "1.1291.1" + resolved "https://registry.yarnpkg.com/@snyk/protect/-/protect-1.1291.1.tgz#45ed75d6d3f0ed14a08566271aed9e5a0a228646" + integrity sha512-Xb9Q4KkZTGOm5BGDBQDnPOU8YmIDUmj9Ub6O1qsCfkGm8Jk+VU6pTl5nhDYS/zmA8n5xJYEYRKUVI9mUZG8Hbg== + "@types/events@*": version "1.2.0" resolved "https://registry.yarnpkg.com/@types/events/-/events-1.2.0.tgz#81a6731ce4df43619e5c8c945383b3e62a89ea86"