Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 1 vulnerabilities #665

Closed

Conversation

ksibisamir
Copy link
Contributor

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 661/1000
Why? Recently disclosed, Has a fix available, CVSS 7.5
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @angular/cli The new version differs by 250 commits.
  • f9527ce release: cut the v17.0.0 release
  • 180dfa3 build: update Angular packages to version 17 stable
  • 8bae6ad release: cut the v17.0.0-rc.5 release
  • 8a9def5 test: add timeout to vite re-use cache
  • 9d4d11c fix(@ angular-devkit/build-angular): allow SSR compilation to work with TS allowJs option
  • ec5e302 refactor(@ schematics/angular): add fallback fonts
  • 3c6d2d8 refactor(@ schematics/angular): remove unused CSS
  • abb1c6f refactor(@ schematics/angular): use control flow to reduce code
  • 81e4917 fix(@ angular/pwa): replace Angular logos
  • ecdcff2 fix(@ schematics/angular): add missing icons in ng-new template
  • 569b714 build: lock file maintenance
  • 303c98c fix(@ angular-devkit/build-angular): normalize exclude path
  • 455aed8 Revert "test: temporary disable Jest E2E tests"
  • 278bfa0 test(@ angular-devkit/build-angular): add test to validate vite cache re-usage
  • a8f041f release: cut the v17.0.0-rc.4 release
  • ae45c4a feat(@ schematics/angular): update `ng new` generated application
  • e10f49e fix(@ angular-devkit/build-angular): convert AOT compiler exceptions into diagnostics
  • 1b38430 fix(@ angular-devkit/build-angular): disable parallel TS/NG compilation inside WebContainers
  • f87f22d fix(@ angular-devkit/build-angular): keep dependencies pre-bundling validate between builds
  • d46fb12 fix(@ angular-devkit/build-angular): disable dependency optimization for SSR
  • 4733cd3 refactor(@ angular-devkit/build-angular): clean externalMetadata arrays on every rebuild
  • a02db0a refactor(@ angular-devkit/build-angular): allow JS transformer result reuse for application dev-server builder
  • 323b005 build: update angular
  • 59c22aa perf(@ angular-devkit/build-angular): start SSR dependencies optimization before the first request

See the full diff

Package name: @angular/localize The new version differs by 250 commits.
  • 8789675 release: cut the v16.0.6 release
  • c58bc97 build: update actions/checkout action to v3.5.3 (#50689)
  • 05ac086 fix(core): avoid duplicated content during hydration while processing a component with i18n (#50644)
  • d154e64 docs: update an example in the RouterEvent description (#50526)
  • 50e1858 build: update all non-major dependencies (#50583)
  • db84fa5 build: lock file maintenance (#50532)
  • 7b5bd77 docs: fix "After you finish" description of first-app-lesson-05.md (#50645)
  • c0a2db9 Revert "test(compiler): Prevent back-sliding on already passing template pipeline tests (#50582)" (#50691)
  • 20953c5 docs: update schematic authoring guide to use new utilities (#50667)
  • 49ad525 build: update AIO to Angular 16.1 (#50667)
  • 97074b8 test(compiler): Prevent back-sliding on already passing template pipeline tests (#50582)
  • 64b21d6 build: update io_bazel_rules_sass digest to 6e0915e (#50605)
  • a0515bf refactor: removed the unused contructor in lazyModule (#50536)
  • 306c42c build: Update Glob to fast-glob to remove Inflight due to memory leak (#50632)
  • 47a1d88 build: update dependency build_bazel_rules_nodejs to v5.8.3 (#50666)
  • 677c7c9 docs: update first-app (#50663)
  • 96bfaa3 docs(core): Add note about testing to NG0203 (#50620)
  • f8920df docs: update first-app-lesson-11.md to include info about routerLink (#50348)
  • 89a089b docs: add missing navigation item (#50113)
  • 8e9f920 docs: added lang attributes in html files (#50588)
  • 33db5f9 docs: removed duplicated words (#50648)
  • 080d62a docs: added title attribute to the iframe tag (#50569)
  • f1b2353 docs(packaging): Clarify the necessity of dev-dependencies (#50619)
  • 140c078 docs: add information about usage of innerHTML and outerHTML (#50643)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
@ksibisamir ksibisamir closed this Mar 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants