diff --git a/goof-yarn/.snyk b/goof-yarn/.snyk
new file mode 100644
index 000000000..111ed0382
--- /dev/null
+++ b/goof-yarn/.snyk
@@ -0,0 +1,20 @@
+# Snyk (https://snyk.io) policy file, patches or ignores known vulnerabilities.
+version: v1.13.3
+ignore: {}
+# patches apply the minimum changes required to fix a vulnerability
+patch:
+  'npm:hawk:20160119':
+    - tap > codecov.io > request > hawk:
+        patched: '2019-03-16T15:19:09.726Z'
+  'npm:http-signature:20150122':
+    - tap > codecov.io > request > http-signature:
+        patched: '2019-03-16T15:19:09.726Z'
+  'npm:mime:20170907':
+    - tap > codecov.io > request > form-data > mime:
+        patched: '2019-03-16T15:19:09.726Z'
+  'npm:request:20160119':
+    - tap > codecov.io > request:
+        patched: '2019-03-16T15:19:09.726Z'
+  'npm:tunnel-agent:20170305':
+    - tap > codecov.io > request > tunnel-agent:
+        patched: '2019-03-16T15:19:09.726Z'
diff --git a/goof-yarn/package.json b/goof-yarn/package.json
index 2300e7e8a..164b48dee 100644
--- a/goof-yarn/package.json
+++ b/goof-yarn/package.json
@@ -10,40 +10,44 @@
   "scripts": {
     "start": "node app.js",
     "build": "browserify -r jquery > public/js/bundle.js",
-    "cleanup": "mongo express-todo --eval 'db.todos.remove({});'"
+    "cleanup": "mongo express-todo --eval 'db.todos.remove({});'",
+    "snyk-protect": "snyk protect",
+    "prepublish": "npm run snyk-protect"
   },
   "engines": {
     "node": "6.14.1"
   },
   "dependencies": {
-    "body-parser": "1.9.0",
+    "body-parser": "1.17.1",
     "cfenv": "^1.0.4",
     "cookie-parser": "1.3.3",
     "consolidate": "0.14.5",
-    "dustjs-linkedin": "2.5.0",
+    "dustjs-linkedin": "2.6.0",
     "dustjs-helpers": "1.5.0",
-    "ejs": "1.0.0",
+    "ejs": "2.5.5",
     "ejs-locals": "1.0.2",
-    "errorhandler": "1.2.0",
-    "express": "4.12.4",
+    "errorhandler": "1.4.3",
+    "express": "4.16.0",
     "express-fileupload": "0.0.5",
-    "humanize-ms": "1.0.1",
-    "jquery": "^2.2.4",
-    "marked": "0.3.5",
+    "humanize-ms": "1.2.1",
+    "jquery": "^3.0.0",
+    "marked": "0.3.17",
     "method-override": "latest",
-    "moment": "2.15.1",
-    "mongoose": "4.2.4",
+    "moment": "2.19.3",
+    "mongoose": "4.13.17",
     "morgan": "latest",
-    "ms": "^0.7.1",
-    "npmconf": "0.0.24",
+    "ms": "^2.0.0",
+    "npmconf": "2.1.3",
     "optional": "^0.1.3",
-    "st": "0.2.4",
+    "st": "1.2.2",
     "stream-buffers": "^3.0.1",
-    "tap": "^5.7.0",
-    "adm-zip": "0.4.7",
-    "file-type": "^8.1.0"
+    "tap": "^11.1.3",
+    "adm-zip": "0.4.11",
+    "file-type": "^8.1.0",
+    "snyk": "^1.136.3"
   },
   "devDependencies": {
     "browserify": "^13.1.1"
-  }
+  },
+  "snyk": true
 }