merlosy / ngx-material-file-input

File input for Angular Material form-field
https://merlosy.github.io/ngx-material-file-input
MIT License
257 stars 63 forks source link

[Snyk] Security upgrade @nrwl/angular from 14.8.4 to 15.5.3 #146

Open merlosy opened 12 months ago

merlosy commented 12 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-SEMVER-3247795](https://snyk.io/vuln/SNYK-JS-SEMVER-3247795) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @nrwl/angular The new version differs by 250 commits.
  • 7285ee5 chore(misc): publish 15.5.3
  • 771fe4a cleanup(angular): enable the ng-cli e2e test (#14503)
  • 22528d1 cleanup(angular): disable ng-add e2e tests temporarily (#14487)
  • c46b24c fix(testing): do not set vitest root when not in workspaceRoot (#14362)
  • 39b5500 feat(webpack): update babel-loader to 9.1.2 to fix hashing issues (#14527)
  • acd2bee fix(bundling): fix esbuild watch yields success=false when no error (#14359)
  • c59d6c7 docs(misc): refine schemas for @ nrwl/workspace (#14522)
  • 1cd1e40 fix(webpack): handle new https options in webpack-dev-server (#14520)
  • 7025e33 fix(testing): update jest snapshots (#14452)
  • c685f34 fix(react): fix imports in tmpl (#14369)
  • 69cb681 fix(vite): remove environments generation (#14515)
  • 7a48c21 fix(testing): fixed a typo with the 15.5.0 cypress migration warning (#14384)
  • df20a01 fix(angular): fix path for import (#14517)
  • 6563ed7 fix(angular): should find the tsconfig at root of project #14379 (#14514)
  • fc9dedf fix(angular): ngrx attaching to route and non-standalone apis for 14 (#14489)
  • 03843ec fix(angular): karma setup should be generated correctly for v14 (#14459)
  • 6d72e3b chore(repo): update CI config to mitigate memory failures (#14502)
  • 91abb6d chore(core): delete accidentally committed file (#14491)
  • 9e8382e docs(react-native): add x-priority to react-native, expo and detox (#14402)
  • 3fa9d43 fix(react): remove unit test runner prompt when generating library (#14457)
  • 22d6519 chore(misc): publish 15.5.2
  • 372334c fix(misc): add missing alt text to files-readme logo (#14446)
  • 2bc9e35 fix(react): install tsconfig-paths-webpack-plugin when converting CRA… (#14442)
  • dfd2916 chore(testing): add lerna-smoke-tests (#14347)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"4d4b6156-5493-46b6-963a-014a21987af3","prPublicId":"4d4b6156-5493-46b6-963a-014a21987af3","dependencies":[{"name":"@nrwl/angular","from":"14.8.4","to":"15.5.3"}],"packageManager":"npm","projectPublicId":"9b55355a-7cab-4674-b062-9e4fedce8b49","projectUrl":"https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-SEMVER-3247795"],"upgrade":["SNYK-JS-SEMVER-3247795"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[768],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lessons/redos/javascript/?loc=fix-pr)