Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build-angular upgrade due to high vulnerabilities #127

Closed
johannesheucher-gip opened this issue Feb 2, 2024 · 0 comments · Fixed by #128
Closed

build-angular upgrade due to high vulnerabilities #127

johannesheucher-gip opened this issue Feb 2, 2024 · 0 comments · Fixed by #128
Assignees

Comments

@johannesheucher-gip
Copy link
Contributor

npm audit

npm audit report

vite 4.0.0 - 4.5.1
Severity: high
Vite dev server option server.fs.deny can be bypassed when hosted on case-insensitive filesystem - GHSA-c24v-8rfc-w8vw
fix available via npm audit fix --force
Will install @angular-devkit/build-angular@16.2.12, which is outside the stated dependency range
node_modules/@angular-devkit/build-angular/node_modules/vite
@angular-devkit/build-angular 16.0.0-next.0 - 16.2.11 || 17.0.0-next.0 - 17.0.10
Depends on vulnerable versions of vite
node_modules/@angular-devkit/build-angular

2 high severity vulnerabilities

To address all issues, run:
npm audit fix --force

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant