From 26825edc754893cfed2819f71c1d6b0f35849c45 Mon Sep 17 00:00:00 2001 From: rmarya-asu Date: Fri, 2 Feb 2018 11:04:36 -0700 Subject: [PATCH] adding Nsp check, and removing Regular expression vulnerability in express 4.15 https://github.com/pillarjs/send/pull/146 the same issue reported on git, shows the regular express vulnerablility, which required me to upgrade the express server, and other dependencies. 2. have added startMessage.js to print start message on dev builds 3. added start and security check scripts to npm. --- package.json | 14 ++++++++++++-- service/scripts/startMessage.js | 2 ++ 2 files changed, 14 insertions(+), 2 deletions(-) create mode 100644 service/scripts/startMessage.js diff --git a/package.json b/package.json index d746fd7..c9e8f5c 100644 --- a/package.json +++ b/package.json @@ -3,15 +3,25 @@ "version": "0.0.0", "private": true, "scripts": { - "start": "node ./service/app.js" + "prestart": "node ./service/scripts/startMessage.js", + "start": "npm-run-all --parallel security-check open:src ", + "open:src": "node ./service/app.js", + "security-check": "nsp check", + "localtunnel": "lt --port 3000", + "share": "npm-run-all --parallel open:src localtunnel" }, "dependencies": { "body-parser": "~1.18.2", "cookie-parser": "~1.4.3", "debug": "~2.6.9", "ejs": "^2.5.7", - "express": "~4.15.5", + "express": "^4.16.2", "morgan": "~1.9.0", "serve-favicon": "~2.4.5" + }, + "devDependencies": { + "chalk": "^2.3.0", + "localtunnel": "^1.8.3", + "npm-run-all": "^4.1.2" } } diff --git a/service/scripts/startMessage.js b/service/scripts/startMessage.js new file mode 100644 index 0000000..8dccea4 --- /dev/null +++ b/service/scripts/startMessage.js @@ -0,0 +1,2 @@ +var chalk = require('chalk'); +console.log(chalk.green('starting app in dev mode ...'));