Skip to content

fix(@angular-devkit/build-angular): update loader-utils to 3.2.1#24242

Merged
dgp1130 merged 1 commit intoangular:13.3.xfrom
alan-agius4:loader-utils-lts
Nov 16, 2022
Merged

fix(@angular-devkit/build-angular): update loader-utils to 3.2.1#24242
dgp1130 merged 1 commit intoangular:13.3.xfrom
alan-agius4:loader-utils-lts

Conversation

@alan-agius4
Copy link
Copy Markdown
Collaborator

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable.

See: GHSA-3rfm-jhwj-7488

Closes #24241

`loader-utils` is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable.

See: GHSA-3rfm-jhwj-7488

Closes angular#24241
@alan-agius4 alan-agius4 added target: lts This PR is targeting a version currently in long-term support action: review The PR is still awaiting reviews from at least one requested reviewer labels Nov 16, 2022
@alan-agius4 alan-agius4 requested a review from clydin November 16, 2022 13:15
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Nov 16, 2022
@dgp1130 dgp1130 merged commit f298ebb into angular:13.3.x Nov 16, 2022
@angular-automatic-lock-bot
Copy link
Copy Markdown

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Dec 17, 2022
@alan-agius4 alan-agius4 deleted the loader-utils-lts branch June 9, 2023 15:04
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants