2018-09-24 08:27:53 +00:00
|
|
|
# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
|
2019-04-12 03:27:47 +00:00
|
|
|
version: v1.13.5
|
2018-09-25 00:16:25 +00:00
|
|
|
# ignores vulnerabilities until expiry date; change duration by modifying expiry date
|
|
|
|
ignore:
|
2019-03-08 10:26:46 +00:00
|
|
|
SNYK-JS-LODASHMERGE-173732:
|
|
|
|
- hexo > cheerio > lodash.merge:
|
2019-07-08 09:07:09 +00:00
|
|
|
reason: >-
|
|
|
|
Patch to be released in lodash@4.17.12. Tracking this PR for release:
|
|
|
|
https://github.com/lodash/lodash/pull/4337
|
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
2019-04-05 01:08:40 +00:00
|
|
|
SNYK-JS-LODASHMERGE-173733:
|
|
|
|
- hexo > cheerio > lodash.merge:
|
2019-07-08 09:07:09 +00:00
|
|
|
reason: >-
|
|
|
|
Patch to be released in lodash@4.17.12. Tracking this PR for release:
|
|
|
|
https://github.com/lodash/lodash/pull/4337
|
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
2019-06-21 04:09:29 +00:00
|
|
|
SNYK-JS-SETVALUE-450213:
|
2019-06-22 04:47:45 +00:00
|
|
|
# snapdragon > base > cache-base > set-value
|
2019-06-21 04:09:29 +00:00
|
|
|
- '*':
|
|
|
|
reason: Patch/update unavailable
|
2019-08-08 07:22:01 +00:00
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
2019-06-21 04:09:29 +00:00
|
|
|
SNYK-JS-MIXINDEEP-450212:
|
2019-06-22 04:47:45 +00:00
|
|
|
# snapdragon > base > mixin-deep
|
2019-06-21 04:09:29 +00:00
|
|
|
- '*':
|
2019-04-12 03:27:47 +00:00
|
|
|
reason: Patch/update unavailable
|
2019-08-08 07:22:01 +00:00
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
2019-07-08 09:07:09 +00:00
|
|
|
SNYK-JS-LODASH-450202:
|
|
|
|
- '*':
|
|
|
|
reason: >-
|
|
|
|
Patch to be released in lodash@4.17.12. Tracking this PR for release:
|
|
|
|
https://github.com/lodash/lodash/pull/4336
|
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
|
|
|
SNYK-JS-MARKED-451341:
|
|
|
|
- '*':
|
|
|
|
reason: >-
|
|
|
|
Patch is released in marked@0.7.0. Tracking this PR for release:
|
|
|
|
https://github.com/hexojs/hexo-renderer-marked/pull/102
|
|
|
|
expires: '2019-08-01T00:00:00.000Z'
|
2019-03-08 10:26:46 +00:00
|
|
|
patch: {}
|