Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @angular-devkit/build-angular from 15.2.10 to 17.1.0 #399

Closed
wants to merge 1 commit into from

Conversation

ludeknovy
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Uncontrolled resource consumption
SNYK-JS-BRACES-6838727
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @angular-devkit/build-angular The new version differs by 250 commits.
  • 27ec067 release: cut the v17.1.0 release
  • 753f726 build: update Angular version ranges for stable v17.1
  • a2ddb9f build: update dependency ng-packagr to v17.1.0
  • 329d800 fix(@ angular-devkit/build-angular): alllow `OPTIONS` requests to be proxied when using `vite`
  • e76950e build: update dependency source-map-loader to v5
  • 537e83e release: cut the v17.1.0-rc.1 release
  • 8cf9777 refactor(@ angular/cli): change Twitter icon in the application schematic
  • b881842 build: update zone.js to 0.14.3
  • b853d0e refactor(@ angular-devkit/build-angular): add experimental builder selector extension for dev-server
  • ca0a836 refactor(@ angular-devkit/build-angular): move diagnostic logging out of build execution
  • 433aef9 refactor(@ angular-devkit/build-angular): move bundler context setup into separate file
  • 2a02b13 fix(@ angular-devkit/build-angular): fix normalization of the application builder extensions
  • ecdad2a ci: re-enable WTR e2e test on Windows
  • 481da20 ci: set `CHROME_PATH` environment variable to Bazel's Chrome install
  • 8c81571 fix(@ schematics/angular): retain existing EOL when adding imports
  • 7f395be fix(@ angular-devkit/core): retain existing EOL when updating workspace config
  • 4a5e708 fix(@ schematics/angular): retain existing EOL when updating JSON files
  • 9f71d2e fix(@ angular/cli): retain existing EOL when updating JSON files
  • b1c7b29 refactor(@ schematics/angular): update server schematic to use new dependency utility
  • 6d7fdb9 fix(@ angular-devkit/build-angular): show diagnostic messages after build stats
  • 626a5ad build: update all non-major dependencies
  • 1d68685 ci: fix `sauce-connect-proxy` version
  • 092da74 refactor: remove `process.cwd` from Web Test Runner builder
  • f192e0f build: update angular

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Uncontrolled resource consumption

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-BRACES-6838727
@ludeknovy ludeknovy closed this Aug 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants