merlosy / ngx-material-file-input

File input for Angular Material form-field
https://merlosy.github.io/ngx-material-file-input
MIT License
257 stars 63 forks source link

[Snyk] Security upgrade @nrwl/angular from 14.8.4 to 16.0.0 #150

Open merlosy opened 7 months ago

merlosy commented 7 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **661/1000**
**Why?** Recently disclosed, Has a fix available, CVSS 7.5 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: @nrwl/angular The new version differs by 250 commits.
  • f537a4c chore(misc): publish 16.0.0
  • 9a14ae4 chore: update nx-cloud to 16.0.5 (#16623)
  • 7660cf6 chore(misc): publish 16.0.0-rc.1
  • c2a0ef0 chore(repo): change more references from @ nrwl to @ nx (#16621)
  • abc5055 chore(repo): update nx to 16.0.0-rc.0 (#16598)
  • b1e3545 fix(core): do not strip additional angular.json properties (#16615)
  • 24b2dee feat(core): remove tasks runner v2 (#16616)
  • 9ed96a1 fix(linter): do not replace legacy package in binary files (#16617)
  • 68f019e chore(core): add missing formatFiles call to migration (#16614)
  • fbf8d9c feat(js): adding simpleName option to library generator (#16025)
  • 43a7d77 cleanup(testing): rename cypress-component-project to cypress-component-configuration (#16382)
  • f91920d docs(core): make migrate latest more prominent (#16596)
  • f004e22 fix(repo): replace remaining instances of yarn with pnpm (#16571)
  • 9d71c71 fix(react): skip DefinePlugin for SSR (#16612)
  • 9753acb fix(core): handle nested gitignores in the filewatcher
  • 2be25eb feat(nest): adding simpleName option to library generator (#16024)
  • e3c50a9 docs(nx-dev): add ProductHunt banner (#16607)
  • 5e2bf07 docs(core): fixing some references to old architect terminology (#16424)
  • 6dd1385 feat(react): refactor util `getModuleFederationConfig` to avoid to pass function to determinate the remote url (#16488)
  • 0947eb4 fix(repo): run nightly e2e with pnpm (#16602)
  • 19e34df chore(misc): publish 16.0.0-rc.0
  • eb425b6 fix(angular): fix the imports of @ angular-devkit/architect/node for n… (#16595)
  • 7b0f96b feat(nx-plugin): simplify generated plugin code (#16590)
  • 010ddee feat(core): update nx schema to include more tasksRunnerOptions options (#16591)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"899b0bb3-443b-4674-bf3a-df27ad6e932e","prPublicId":"899b0bb3-443b-4674-bf3a-df27ad6e932e","dependencies":[{"name":"@nrwl/angular","from":"14.8.4","to":"16.0.0"}],"packageManager":"npm","projectPublicId":"9b55355a-7cab-4674-b062-9e4fedce8b49","projectUrl":"https://app.snyk.io/org/merlosy/project/9b55355a-7cab-4674-b062-9e4fedce8b49?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-INFLIGHT-6095116"],"upgrade":["SNYK-JS-INFLIGHT-6095116"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[661],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Learn about vulnerability in an interactive lesson of Snyk Learn.](https://learn.snyk.io/?loc=fix-pr)