hackariens / angular

Templates pour la crΓ©ation d'un nouveau projet angular
0 stars 1 forks source link

chore(deps): update dependency minimatch to 3.0.5 [security] - autoclosed #149

Closed renovate[bot] closed 1 year ago

renovate[bot] commented 1 year ago

Mend Renovate

This PR contains the following updates:

Package Change
minimatch 3.0.4 -> 3.0.5

GitHub Vulnerability Alerts

CVE-2022-3517

A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.


Configuration

πŸ“… Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

β™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

πŸ”• Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Mend Renovate. View repository job log here.

renovate[bot] commented 1 year ago

⚠ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

β™» Renovate will retry this branch, including artifacts, only when one of the following happens:

The artifact failure details are included below:

File name: apps/package-lock.json
npm ERR! code ERESOLVE
npm ERR! ERESOLVE unable to resolve dependency tree
npm ERR! 
npm ERR! While resolving: apps@0.0.0
npm ERR! Found: typescript@4.2.3
npm ERR! node_modules/typescript
npm ERR!   dev typescript@"4.2.3" from the root project
npm ERR! 
npm ERR! Could not resolve dependency:
npm ERR! peer typescript@">=4.0 <4.2" from @angular/compiler-cli@11.2.6
npm ERR! node_modules/@angular/compiler-cli
npm ERR!   dev @angular/compiler-cli@"11.2.6" from the root project
npm ERR! 
npm ERR! Fix the upstream dependency conflict, or retry
npm ERR! this command with --force, or --legacy-peer-deps
npm ERR! to accept an incorrect (and potentially broken) dependency resolution.
npm ERR! 
npm ERR! See /tmp/renovate-cache/others/npm/eresolve-report.txt for a full report.

npm ERR! A complete log of this run can be found in:
npm ERR!     /tmp/renovate-cache/others/npm/_logs/2023-01-18T14_02_31_605Z-debug-0.log
guardrails[bot] commented 1 year ago

:warning: We detected 5 security issues in this pull request:

Vulnerable Libraries (5)
Severity | Details ----- | -------- Critical | [ejs@3.1.6](https://github.com/koromerzhin/template-angular/blob/23f92ecdd7cc8bf4028bb5dc2f17ca572d98da0c/apps/package-lock.json) (t) upgrade to: *>=3.1.7* High | [koromerzhin-dependencies@1.3.0](https://github.com/koromerzhin/template-angular/blob/23f92ecdd7cc8bf4028bb5dc2f17ca572d98da0c/apps/package.json) (t) upgrade to: *>=1.0.1* Medium | [lock-verify@2.2.1](https://github.com/koromerzhin/template-angular/blob/23f92ecdd7cc8bf4028bb5dc2f17ca572d98da0c/apps/package-lock.json) (t) upgrade to: *>1.1.0 || >2.2.1* Medium | [semantic-git-commit-cli@3.7.0](https://github.com/koromerzhin/template-angular/blob/23f92ecdd7cc8bf4028bb5dc2f17ca572d98da0c/apps/package-lock.json) (t) upgrade to: *>=1.1.0* Critical | [@angular-devkit/build-angular@13.3.2](https://github.com/koromerzhin/template-angular/blob/23f92ecdd7cc8bf4028bb5dc2f17ca572d98da0c/apps/package.json#L27) upgrade to: *>13.3.8 || >14.1.0-rc.3* More info on how to fix Vulnerable Libraries in [JavaScript](https://docs.guardrails.io/docs/en/vulnerabilities/javascript/using_vulnerable_libraries.html?utm_source=ghpr#).

πŸ‘‰ Go to the dashboard for detailed results.

πŸ“₯ Happy? Share your feedback with us.