mgechev / codelyzer

Static analysis for Angular projects.
http://codelyzer.com/
MIT License
2.45k stars 233 forks source link

Update Angular to resolve vulnerability CVE-2021-4231 #1033

Open NotTheSamAdamsGuy opened 2 years ago

NotTheSamAdamsGuy commented 2 years ago

Versions of Angular < 11.0.5 have a cross-site scripting vulnerability as described at https://github.com/advisories/GHSA-c75v-2vq8-878f.

ahoss63 commented 1 year ago

same issue here due to the version 9.0.0 of @angular/core referenced in package.json any info about when the correction will be shipped ?

amanyzohair commented 1 year ago

Same issue A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2

jponce-meyler commented 1 year ago

If you install this dependency as a dev dependency is still a problem but not that important and as I understood should be always a dev dependency