{"_id":"@asos/snyker","_rev":"11-e92ab8a352c7f04dd4a0ccae60c18d0b","name":"@asos/snyker","dist-tags":{"latest":"5.1.0"},"versions":{"4.0.0":{"name":"@asos/snyker","version":"4.0.0","keywords":["snyk","security","vulnerabilities"],"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","_id":"@asos/snyker@4.0.0","maintainers":[{"name":"asos-bradleyabel","email":"bradley.abel@asos.com"},{"name":"asos-craigmorten","email":"craig.morten@asos.com"},{"name":"asos-rupeshghelani","email":"rupesh.ghelani@asos.com"}],"homepage":"https://github.com/asos/snyker#README","bugs":{"url":"https://github.com/asos/snyker/issues"},"bin":{"snyker":"bin/snyker"},"dist":{"shasum":"578122a3dc44c5dfe8cf32fc459f0f24d9c533fc","tarball":"https://registry.npmjs.org/@asos/snyker/-/snyker-4.0.0.tgz","fileCount":11,"integrity":"sha512-gBOn7vMkAItrt6zlAJlXeS/ipK1ouwp07+TkU/TQBcgVTx9cvyWYQxxISqFA9GMD7vssS9RgYRrNYzvyTbMdUA==","signatures":[{"sig":"MEQCIG9ZjzHZFTzSfpJQzXTDizJWjnCuwHf3pHx70Ld7akhSAiB3Ohcukkwj37OGpNIfQzVuXqXKhCelU3F+bxgR6XW/Uw==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":83893,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhuJogCRA9TVsSAnZWagAAKToP+QB8FwZoBYBhH2bfAnLe\nOwE007Yd19x+go3Vq3lV9wldbrwDZwNEHnI2Cut0WGz81g6Vr8VsGp85jlvf\nY8gPswejDAeb92M3OFIGpH7/4q0Rb4nS9x4g1JlyN5NEWKAPn0NzUIG1CK6W\nAnnaZilC5rX+0VZueGIdPdWUQRFz8+l+tYd4frRTeBvVIehIhTMbMeKqM6iv\nhbOD7fD02lcUlXxFf0CrB6fbTTbURGUBLGHMhIh69H9+b1WqO1hd/1OudBeX\nWzblIZaWw7ArPLQNHyAi9zZmKiYpqwdnWZ/EGxjyZNfU00UcqCsdTcN7SGpo\nmUspjCVLkVLCj0F5VOncyWxQaoYT5gmguu6JPLnluKQ0czyztmICu+UhKTrO\niK8HmSVLqWkBGlykVaYHZ7KUg/jIxJqomGszNqEpUyhv7JsJCagCCmbifBa7\nHlWCPmgF6+aqTCxXWeQAmnh7lap6y9KeqnQYR1fSRmd6WGMk94+fLXE+Kv/w\nDazZK9zEIXv3w2qG3puWs+bTvsBICbZ90Cz2aPXkH3lVLQvTmIDU4YPJA2aj\nwFCrnI+FjzMWQ2RJvD7HD9/dZNj0Ng6NVsgdU1j51E8bZmR9ioNV53sKJXts\niXQSWcpnfbmyELfeKuGvpnm03NjJ8p73sAbGjyDp+kpihYfIggIgvOs+9E7T\n1MDO\r\n=HwsB\r\n-----END PGP SIGNATURE-----\r\n"},"main":"lib/index.js","scripts":{"ci":"yarn clean && yarn lint && yarn build && yarn snyker && yarn snyker:npm","lint":"eslint ./src","build":"cross-env BABEL_ENV=node rollup -c server.rollup.js","clean":"yarn clean:lib && yarn clean:lock","snyker":"bin/snyker","lint:fix":"yarn lint --fix","clean:lib":"rimraf lib","clean:lock":"rimraf package-lock.json","snyker:npm":"bin/snyker --lockfile=package-lock.json && yarn clean:lock","prepublishOnly":"yarn ci"},"_npmUser":{"name":"asos-craigmorten","email":"craig.morten@asos.com"},"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","directories":{},"licenseText":"MIT License\n\nCopyright (c) 2021 ASOS\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","dependencies":{"snyk":"^1.790.0","yargs":"^17.3.0","js-yaml":"^4.1.0","@yarnpkg/lockfile":"^1.1.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^8.4.1","rimraf":"^3.0.2","rollup":"^2.61.1","prettier":"^2.5.1","cross-env":"^7.0.3","@babel/core":"^7.16.5","rollup-plugin-json":"^4.0.0","rollup-plugin-babel":"^4.4.0","eslint-plugin-import":"^2.25.3","rollup-plugin-terser":"^7.0.2","eslint-config-prettier":"^8.3.0","eslint-plugin-prettier":"^4.0.0","rollup-plugin-commonjs":"^10.1.0","rollup-plugin-node-resolve":"^5.2.0"},"_npmOperationalInternal":{"tmp":"tmp/snyker_4.0.0_1639488032565_0.05788990484244261","host":"s3://npm-registry-packages"}},"4.0.1":{"name":"@asos/snyker","version":"4.0.1","keywords":["snyk","security","vulnerabilities"],"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","_id":"@asos/snyker@4.0.1","maintainers":[{"name":"asos-bradleyabel","email":"bradley.abel@asos.com"},{"name":"asos-craigmorten","email":"craig.morten@asos.com"},{"name":"asos-rupeshghelani","email":"rupesh.ghelani@asos.com"}],"homepage":"https://github.com/asos/snyker#README","bugs":{"url":"https://github.com/asos/snyker/issues"},"bin":{"snyker":"bin/snyker"},"dist":{"shasum":"0fd1fc7cab43ae5ef3fb072a156f2beba0b73023","tarball":"https://registry.npmjs.org/@asos/snyker/-/snyker-4.0.1.tgz","fileCount":11,"integrity":"sha512-eLAayYOMSY/zel+YdBoR437tKCY9e9NKEpnthJPUfi8RGi5iszKyEtqZ01Uk37ld0jEO3Ycjcfadh/Pf2uZHJg==","signatures":[{"sig":"MEQCIA7OB28VaJl6ddK7Nm1IVac+AXYZvDg+tal5owogdXb1AiA2KbsCDK+N8sa58JcI7z9I5lftWTXQBLc+c5VZpVy58w==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":83990,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhuJz3CRA9TVsSAnZWagAAYNgP/0uO94Lk5Vk0NyecbR3X\njO0dRiSxejBRrqmdzCvG5g+uSGuUeb1KQton+xJ51Xtql/iEIVFDZDkoDXzd\nLW3Ynxq2gynm1KocTNQKAn0cZB15hc8x90ZtNXJtVBgf000lZagHawqYuR05\nLJ0ZnoM1eZYHWbS3QY7E4tkbW4+mE4QUQ9eWh0vBj728E4xBIpyMumvqjksp\npL3BH9KeBH1M3PC+fAD8ynj/CvJOaTx9AWWeOvaPktxFO1SATF6QKOJwV1e6\n4tix0+LhT76InA5H5c9iScQnNvFyvDZHaq9e05o9sR4Z9Tvb9hW3fVyLz5Ex\nuQpwZxRRG+MPwIxHfgChiM4zR2lzAf/gmmpCSAers38RPRTRHPLh55JNrXaO\npY+y1fjcGgFMr8xTCw6wHcCJ9e8zaXYS7cTKcS/KM8bua8QIskLtCuy9eDH3\nP/Tp05Dhn6NxNEOjcx1v9T4MZQo7E7N0WeSEddZGRD4hRW+elXND2dCChrcM\nYwT7xNWaHtNfuFXWhDnTRw1g5iI8mRyvtRU/Sp/WvqksNRLXHR6QMJV18al6\n8B+MQ/btzdp7ATVwgBBH1/adIynUKjxoGjIGHiOYuJrER2F+4usDkEziIptz\n5ivFplppwDLkmw1NySZ3oEFXN3aZrW2cJ6K+MSza9Y6jBdgm8XfKU2C62Ove\n/Uhl\r\n=ZuBe\r\n-----END PGP SIGNATURE-----\r\n"},"main":"lib/index.js","scripts":{"ci":"yarn clean && yarn lint && yarn build && yarn snyker && yarn snyker:npm","lint":"eslint ./src","build":"cross-env BABEL_ENV=node rollup -c server.rollup.js","clean":"yarn clean:lib && yarn clean:lock","snyker":"bin/snyker","lint:fix":"yarn lint --fix","clean:lib":"rimraf lib","clean:lock":"rimraf package-lock.json","snyker:npm":"bin/snyker --lockfile=package-lock.json && yarn clean:lock","prepublishOnly":"yarn ci"},"_npmUser":{"name":"asos-craigmorten","email":"craig.morten@asos.com"},"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","directories":{},"licenseText":"MIT License\n\nCopyright (c) 2021 ASOS\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","dependencies":{"snyk":"^1.790.0","yargs":"^17.3.0","js-yaml":"^4.1.0","@yarnpkg/lockfile":"^1.1.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^8.4.1","rimraf":"^3.0.2","rollup":"^2.61.1","prettier":"^2.5.1","cross-env":"^7.0.3","@babel/core":"^7.16.5","rollup-plugin-json":"^4.0.0","rollup-plugin-babel":"^4.4.0","eslint-plugin-import":"^2.25.3","rollup-plugin-terser":"^7.0.2","eslint-config-prettier":"^8.3.0","eslint-plugin-prettier":"^4.0.0","rollup-plugin-commonjs":"^10.1.0","rollup-plugin-node-resolve":"^5.2.0"},"_npmOperationalInternal":{"tmp":"tmp/snyker_4.0.1_1639488758920_0.6668806083908816","host":"s3://npm-registry-packages"}},"4.0.2":{"name":"@asos/snyker","version":"4.0.2","keywords":["snyk","security","vulnerabilities"],"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","_id":"@asos/snyker@4.0.2","maintainers":[{"name":"asos-bradleyabel","email":"bradley.abel@asos.com"},{"name":"asos-craigmorten","email":"craig.morten@asos.com"},{"name":"asos-rupeshghelani","email":"rupesh.ghelani@asos.com"}],"homepage":"https://github.com/asos/snyker#README","bugs":{"url":"https://github.com/asos/snyker/issues"},"bin":{"snyker":"bin/snyker"},"dist":{"shasum":"87c56ce2b7b6ad80bf33d0d41685593a22b4895d","tarball":"https://registry.npmjs.org/@asos/snyker/-/snyker-4.0.2.tgz","fileCount":11,"integrity":"sha512-OM3X3ioTiJDLLnfla8JZuz2paR+ybSF2LuXf/xvS4yD2M+m1/0mpFi4OJ62EJpVAso74dpAbPy6Z0gOTQQ6XBA==","signatures":[{"sig":"MEUCIFH5Evd/Qm/5kYL2tIxS0MsodDJSA0VWOUK0lE2B/q96AiEAqqoURxRSVqxVfj2/XtgR6d+fizWi1PhhBtJ+6pdwFKM=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":84088,"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v3.0.13\r\nComment: https://openpgpjs.org\r\n\r\nwsFcBAEBCAAQBQJhuzs2CRA9TVsSAnZWagAAiSIP/AhJL/KByvB2ntCZ/CTF\nmhWk1SNMWWywEthSNd/1qEvUW2sMsC6aEWn+vLwey9nShZQzwoICZNOIFszV\nGP0KkoPKBbNlqS/Hz/IDFRHyQjP7x+bvjNgTvFi1OBUvkcKnJyAmIgOIQ6g+\nBhbeNE8tTLCGCbVNYc5UUKpKIne9b/vA1GJEFLLmhhCoCp8HRazgNfWZT4Pg\nydArVk2UwNVBmeVibdvOdqOi6zpgXqi/GTRfb+C1dpK0AXWldvUOgDFdfVB0\nXIOz59uqNeCyyNYvBZZypgUiy1Ap5jHP33OUmhnA/wtnwkoiusP0zdw9kkoR\n1IRLDyUtwCmQHiJFnmLdBBv4SNzqHx5SZHjMokf8RipaY04hBL8JQcshzYNU\nLYqdz/jpWk3FPHDxRRqfoYY/iD7mOWy9+JfLlcFZbKVi3qjdVT02I9+SWqPN\n7N0mbO3MsDpVpiE/qyFW73uEW8nTJzbkmniInF4jX8J6X9Fxeoe6NuqsgH4i\nq38FiGUEdDZ3BEoswX4Ua6uuwc3ALplAfzVcR1Vgwn7mzlZExicX3cuoOGCM\nvdXmi3CSTmL/lOQv+yLFdaddRGI6gKMIHgyMGVPTd1DjwKOEAIYBPlIsF08w\nxY3Kwh78g7dE93Y2zixpj4UWB8MxIV7WN5lUA6Hom5b+kViOqm6oskfSYnP+\n5fmp\r\n=1Jyp\r\n-----END PGP SIGNATURE-----\r\n"},"main":"lib/index.js","engines":{"npm":">=5.2.0"},"scripts":{"ci":"yarn clean && yarn lint && yarn build && yarn snyker && yarn snyker:npm","lint":"eslint ./src","build":"cross-env BABEL_ENV=node rollup -c server.rollup.js","clean":"yarn clean:lib && yarn clean:lock","snyker":"bin/snyker","lint:fix":"yarn lint --fix","clean:lib":"rimraf lib","clean:lock":"rimraf package-lock.json","snyker:npm":"bin/snyker --lockfile=package-lock.json && yarn clean:lock","prepublishOnly":"yarn ci"},"_npmUser":{"name":"asos-craigmorten","email":"craig.morten@asos.com"},"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","directories":{},"licenseText":"MIT License\n\nCopyright (c) 2021 ASOS\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","dependencies":{"snyk":"^1.790.0","yargs":"^17.3.0","js-yaml":"^4.1.0","@yarnpkg/lockfile":"^1.1.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^8.4.1","rimraf":"^3.0.2","rollup":"^2.61.1","prettier":"^2.5.1","cross-env":"^7.0.3","@babel/core":"^7.16.5","rollup-plugin-json":"^4.0.0","rollup-plugin-babel":"^4.4.0","eslint-plugin-import":"^2.25.3","rollup-plugin-terser":"^7.0.2","eslint-config-prettier":"^8.3.0","eslint-plugin-prettier":"^4.0.0","rollup-plugin-commonjs":"^10.1.0","rollup-plugin-node-resolve":"^5.2.0"},"_npmOperationalInternal":{"tmp":"tmp/snyker_4.0.2_1639660342481_0.4784793659060007","host":"s3://npm-registry-packages"}},"5.0.0":{"name":"@asos/snyker","version":"5.0.0","keywords":["snyk","security","vulnerabilities"],"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","_id":"@asos/snyker@5.0.0","maintainers":[{"name":"asos-bradleyabel","email":"bradley.abel@asos.com"},{"name":"asos-rupeshghelani","email":"rupesh.ghelani@asos.com"},{"name":"asos-roberth","email":"robert.hill@asos.com"},{"name":"asos-tonygorman","email":"Tony.Gorman@asos.com"},{"name":"asos-danielc","email":"DanielC@ASOS.com"}],"homepage":"https://github.com/asos/snyker#README","bugs":{"url":"https://github.com/asos/snyker/issues"},"bin":{"snyker":"bin/snyker"},"dist":{"shasum":"a6d8b2ae8ebb4552d40cc57ca03bc1ae708ecdcf","tarball":"https://registry.npmjs.org/@asos/snyker/-/snyker-5.0.0.tgz","fileCount":11,"integrity":"sha512-vaitQeyIMHxNGdwo0VgBbD8p+9ZLVTOcfg6nsanZP+3S0zSJIPeZa/j2P3uqumCi9PZ8JgfNFqKykhXooUylIQ==","signatures":[{"sig":"MEQCIAIwT3sCDSbPflH3wAtavM8OEV4d8/zRSC4UCTbx3hvtAiBJNf0L7ZOuglwqPnwUs9DAANMcHhbo335JeW3yp/DOFQ==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":118170},"main":"lib/index.js","engines":{"npm":">=9.0.0"},"scripts":{"ci":"yarn clean && yarn lint && yarn build && yarn snyker && yarn snyker:npm","lint":"ESLINT_USE_FLAT_CONFIG=false eslint ./src","build":"cross-env BABEL_ENV=node rollup -c server.rollup.js --bundleConfigAsCjs","clean":"yarn clean:lib && yarn clean:lock","snyker":"bin/snyker","lint:fix":"yarn lint --fix","clean:lib":"rimraf lib","clean:lock":"rimraf package-lock.json","snyker:npm":"bin/snyker --lockfile=package-lock.json && yarn clean:lock","prepublishOnly":"yarn ci"},"_npmUser":{"name":"asos-danielc","email":"DanielC@ASOS.com"},"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","directories":{},"licenseText":"MIT License\n\nCopyright (c) 2021 ASOS\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","dependencies":{"snyk":"^1.790.0","yargs":"^17.3.0","js-yaml":"^4.1.0","@yarnpkg/lockfile":"^1.1.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.10.0","rimraf":"^6.0.1","rollup":"^4.21.2","prettier":"^3.3.3","cross-env":"^7.0.3","@babel/core":"^7.16.5","@rollup/plugin-json":"^6.1.0","@rollup/plugin-babel":"^6.0.4","eslint-plugin-import":"^2.30.0","@rollup/plugin-terser":"^0.4.4","eslint-config-prettier":"^9.1.0","eslint-plugin-prettier":"^5.2.1","@rollup/plugin-commonjs":"^26.0.1","@rollup/plugin-node-resolve":"^15.2.3"},"_npmOperationalInternal":{"tmp":"tmp/snyker_5.0.0_1733227205488_0.9785275688735162","host":"s3://npm-registry-packages"}},"5.1.0":{"name":"@asos/snyker","version":"5.1.0","keywords":["snyk","security","vulnerabilities"],"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","_id":"@asos/snyker@5.1.0","maintainers":[{"name":"asos-bradleyabel","email":"bradley.abel@asos.com"},{"name":"asos-rupeshghelani","email":"rupesh.ghelani@asos.com"},{"name":"asos-roberth","email":"robert.hill@asos.com"},{"name":"asos-tonygorman","email":"Tony.Gorman@asos.com"},{"name":"asos-danielc","email":"DanielC@ASOS.com"}],"homepage":"https://github.com/asos/snyker#README","bugs":{"url":"https://github.com/asos/snyker/issues"},"bin":{"snyker":"bin/snyker"},"dist":{"shasum":"b7e3ae9f4ab22f314fe9a06be30b2101e7e06afb","tarball":"https://registry.npmjs.org/@asos/snyker/-/snyker-5.1.0.tgz","fileCount":11,"integrity":"sha512-/W31P6qptxiZ/ZJozyWV1F6HDZEBHc2TbWyp3whsPkfeXnhR9gkN3p7ChHa2F0v0ZdyIwtd1Mrk7BU4lJSI1hA==","signatures":[{"sig":"MEQCIFeHVhH/ms6V7a2uOZytJzYvfp9JpXeqNFY5CUVaB0gLAiB5XMyF9PSMktQjHpBgKSPHTwhsIeK9wYT2rqFRrDkF9g==","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":122703},"main":"lib/index.js","engines":{"npm":">=9.0.0"},"scripts":{"ci":"yarn clean && yarn lint && yarn build && yarn snyker && yarn snyker:npm","lint":"ESLINT_USE_FLAT_CONFIG=false eslint ./src","build":"cross-env BABEL_ENV=node rollup -c server.rollup.js --bundleConfigAsCjs","clean":"yarn clean:lib && yarn clean:lock","snyker":"bin/snyker","lint:fix":"yarn lint --fix","clean:lib":"rimraf lib","clean:lock":"rimraf package-lock.json","snyker:npm":"bin/snyker --lockfile=package-lock.json && yarn clean:lock","prepublishOnly":"yarn ci"},"_npmUser":{"name":"asos-danielc","email":"DanielC@ASOS.com"},"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","directories":{},"licenseText":"MIT License\n\nCopyright (c) 2021 ASOS\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.\n","dependencies":{"snyk":"^1.790.0","yargs":"^17.3.0","js-yaml":"^4.1.0","@yarnpkg/lockfile":"^1.1.0"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^9.10.0","rimraf":"^6.0.1","rollup":"^4.21.2","prettier":"^3.3.3","cross-env":"^7.0.3","@babel/core":"^7.16.5","@rollup/plugin-json":"^6.1.0","@rollup/plugin-babel":"^6.0.4","eslint-plugin-import":"^2.31.0","@rollup/plugin-terser":"^0.4.4","eslint-config-prettier":"^9.1.0","eslint-plugin-prettier":"^5.2.1","@rollup/plugin-commonjs":"^26.0.1","@rollup/plugin-node-resolve":"^15.2.3"},"_npmOperationalInternal":{"tmp":"tmp/snyker_5.1.0_1733227690408_0.2663329390793263","host":"s3://npm-registry-packages"}}},"time":{"created":"2021-12-14T13:20:32.523Z","modified":"2025-10-17T10:32:24.435Z","4.0.0":"2021-12-14T13:20:32.706Z","4.0.1":"2021-12-14T13:32:39.092Z","4.0.2":"2021-12-16T13:12:22.628Z","5.0.0":"2024-12-03T12:00:05.712Z","5.1.0":"2024-12-03T12:08:10.611Z"},"bugs":{"url":"https://github.com/asos/snyker/issues"},"author":{"name":"Craig Morten","email":"craig.morten@asos.com"},"license":"MIT","homepage":"https://github.com/asos/snyker#README","keywords":["snyk","security","vulnerabilities"],"repository":{"url":"git+https://github.com/asos/snyker.git","type":"git"},"description":"An opinionated, heavy-handed wrapper around Snyk.","maintainers":[{"email":"robert.hill@asos.com","name":"asos-roberth"},{"email":"Tony.Gorman@asos.com","name":"asos-tonygorman"},{"email":"DanielC@ASOS.com","name":"asos-danielc"}],"readme":"<p align=\"center\">\n  <h1 align=\"center\">Snyker</h1>\n</p>\n<p align=\"center\">\nAn opinionated CLI wrapper around <a href=\"https://snyk.io/\">Snyk</a> for purging vulnerabilities from Node projects\n</p>\n<p align=\"center\">\n   <a href=\"https://github.com/asos/snyker/tags/\"><img src=\"https://img.shields.io/github/tag/asos/snyker\" alt=\"Current version\" /></a>\n   <img src=\"https://github.com/asos/snyker/workflows/Test/badge.svg\" alt=\"Current test status\" />\n   <a href=\"http://makeapullrequest.com\"><img src=\"https://img.shields.io/badge/PRs-welcome-brightgreen.svg\" alt=\"PRs are welcome\" /></a>\n   <a href=\"https://github.com/asos/snyker/issues/\"><img src=\"https://img.shields.io/github/issues/asos/snyker\" alt=\"snyker issues\" /></a>\n   <img src=\"https://img.shields.io/github/stars/asos/snyker\" alt=\"snyker stars\" />\n   <img src=\"https://img.shields.io/github/forks/asos/snyker\" alt=\"snyker forks\" />\n   <img src=\"https://img.shields.io/github/license/asos/snyker\" alt=\"snyker license\" />\n   <a href=\"https://github.com/asos/snyker/graphs/commit-activity\"><img src=\"https://img.shields.io/badge/Maintained%3F-yes-green.svg\" alt=\"snyker is maintained\" /></a>\n</p>\n<p align=\"center\">\n  <i>You're not you when you've got hundreds of vulnerable paths</i>\n</p>\n\n---\n\n## Getting Started\n\n```bash\n# Start fixing vulnerabilities straight away using NPX\nnpx @asos/snyker\n\n# Add to your global NPM packages\nnpm i -g @asos/snyker\n\n# Or to your global Yarn packages\nyarn global add @asos/snyker\n```\n\n## About\n\nThe Snyk CLI is great for reporting vulnerabilities and providing top level dependency upgrades and patches, but struggles when the vulnerability rests within a nested \"transitive\" sub-dependency. This is despite the fact that many sub-dependencies have reasonable flexibility in the version ranges they allow for their own dependencies.\n\nThis CLI takes a brute-force approach to solving this limitation of Snyk. It purges the `.snyk` file from a project, checks for vulnerable paths using Snyk, then forces `yarn` / `npm` to try to upgrade any dependency along the vulnerable paths before finally ignoring any vulnerability that cannot be fixed in the previous steps. If a patch is available for any outstanding vulnerability then it is also added to the Snyk policy.\n\nNote that this tool obeys your defined package version ranges and therefore can't fix anything that requires a major upgrade if you are only permitting minor or patch upgrades.\n\nThis tool also does not make use of Snyk's ability to perform package major upgrades. It will simply ignore vulnerabilities that cannot be fixed in the aforementioned steps. _It is on you to sanity check anything that this tool decides to ignore._\n\nSnyker will list the known vulnerabilities it has been unable to fix. If Snyk reports that there are major upgrades available to fix one or more of the outstanding vulnerabilities, Snyker will output a recommended `yarn` / `npm` command for performing the upgrade(s).\n\nIt is recommended that you use this tool alongside the official Snyk CLI, not replace it completely.\n\n## Usage\n\n### Options\n\n```console\nsnyker --retries 3 --lockfile package-lock.json --preserve-integrity\n```\n\n| Flag                   | Description                                                              | Default     |\n| ---------------------- | -------------------------------------------------------------------------| ----------- |\n| `--lockfile <string>`  | Specify the lockfile to use (e.g. `yarn.lock` or `package-lock.json`).   | Attempts to find a `yarn.lock` or `package-lock.json` then defaults to `yarn.lock` |\n| `--retries <int>`      | Will set the number of times to retry logical steps of Snyker.           | `2`         |\n| `--preserve-integrity` | Will not attempt to update integrity hash when `sha1` is used. \\*        | `false`     |\n\n> \\* It is highly recommended to use `sha512` for the integrity hash algorithm which is default for `npm`. However, when using private repositories such as Azure Artifacts, they do not support anything other than `sha1`. In turn, if the integrity is removed, the subsequent `npm install` command does not re-instate these. This flag is a workaround for this issue.\n\n## Alternatives\n\n### Snyk Pull Requests\n\n[Snyk supports a pull or merge request integration](https://docs.snyk.io/scan-using-snyk/pull-requests/snyk-fix-pull-or-merge-requests) for your source control repositories which can upgrade your dependencies based on scan results.\n\nThis behaves similar to Snyker in providing a capability to upgrade dependencies, but is not available as a CLI and does not bundle ignore behaviours at the same time.\n\n### Snyk Ignore\n\nThe Snyk CLI supports a [`snyk ignore` command](https://github.com/snyk/cli/blob/main/help/cli-commands/ignore.md) to ignore a stated issue according to its snyk ID for all occurrences, its expiry date, a reason, or according to paths in the filesystem.\n\nThis commands does not perform any dependency upgrades and requires you to manually look up the vulnerability's ID to execute the correct ignore command.\n\nSnyker currently includes the `snyk ignore` capability as part of it's process.\n\n### Snyk Protect\n\nSnyk supports a separate [`@snyk/protect`](https://github.com/snyk/cli/tree/main/packages/snyk-protect#readme) CLI, replacing the older `snyk protect` command for patching vulnerable dependencies.\n\nThe Snyker maintainers generally advise against the usage of closed source patches for your dependencies.\n\n### Snyk Fix\n\nSnyk has released a [closed beta](https://docs.snyk.io/getting-started/snyk-release-process#closed-beta) [`snyk fix` command](https://docs.snyk.io/snyk-cli/scan-and-maintain-projects-using-the-cli/automatic-fixing-with-snyk-fix) that aims to automatically apply the recommended updates, but this is currently only available for Enterprise customers using Python.\n\n### Snyk Wizard\n\nSnyk used to support a `snyk wizard` command which would perform dependency upgrades and policy ignores [but this was removed on 31 March 2022](https://updates.snyk.io/snyk-wizard-and-snyk-protect-removal-224137).\n\n## Contributing\n\nPlease check out the [CONTRIBUTING](./docs/CONTRIBUTING.md) docs.\n\n## Changelog\n\nPlease check out the [CHANGELOG](./docs/CHANGELOG.md) docs.\n\n---\n\n## License\n\nSnyker is licensed under the [MIT License](./LICENSE).\n","readmeFilename":"README.md"}