santebe / AppWeb-JuiceShopDevSec

MIT License
0 stars 0 forks source link

[Snyk] Upgrade zone.js from 0.11.8 to 0.14.5 #61

Closed santebe closed 4 months ago

santebe commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade zone.js from 0.11.8 to 0.14.5.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **11 versions** ahead of your current version. - The recommended version was released **22 days ago**, on 2024-04-30. The recommended version fixes: Severity | Issue | PriorityScore (\*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Uncontrolled resource consumption
[SNYK-JS-BRACES-6838727](/SNYK-JS-BRACES-6838727) | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | Proof of Concept | Inefficient Regular Expression Complexity
[SNYK-JS-MICROMATCH-6838728](/SNYK-JS-MICROMATCH-6838728) | **768/1000**
**Why?** Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5 | No Known Exploit (\*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: zone.js
  • 0.14.5 - 2024-04-30
  • 0.14.4 - 2024-02-13
  • 0.14.3 - 2024-01-09
  • 0.14.2 - 2023-11-03
  • 0.14.1 - 2023-10-26
  • 0.14.0 - 2023-09-18
  • 0.13.3 - 2023-09-12
  • 0.13.2 - 2023-09-11
  • 0.13.1 - 2023-06-12
  • 0.13.0 - 2023-03-06
  • 0.12.0 - 2022-11-07
  • 0.11.8 - 2022-08-12
from zone.js GitHub release notes
Commit messages
Package name: zone.js
  • ff65669 release: cut the zone.js-0.14.5 release (#55599)
  • 0a77825 build: improve incremental rebuilds of compliance tests (#55594)
  • a4a82af docs(core): add documentation for errors NG0955 and NG0956 (#55591)
  • 375e9a7 build: update scorecard action dependencies (#55589)
  • 66ffeca fix(router): Scroller should scroll as soon as change detection completes (#55105)
  • fd54415 ci: complete migration to prettier formatting (#55580)
  • 49d3062 docs(docs-infra): allow file renaming in code editor (#54989)
  • 9160a21 docs: add mention of the HTTP client for interceptors (#55551)
  • 0650981 docs: fix broken link to error doc (#55547)
  • b87a4c4 docs: update NgClass example description to match the example's behavior (#55209)
  • 4f9084e docs: show the difference between pseudo classes angular uses and native ones in runtime (#53819)
  • 292c987 refactor(compiler): add `handler` attribute to XMB output (#54865)
  • 0d78a92 refactor: migrate compiler-cli to prettier formatting (#55485)
  • f307e95 refactor: migrate zone.js to prettier formatting (#55427)
  • 31fdf0f refactor: migrate core to prettier formatting (#55488)
  • be17de5 refactor(core): Permit disabling autoDetect for zoneless fixture (#55494)
  • 91b1f24 fix(migrations): resolve multiple structural issues with HttpClient migration (#55557)
  • 4a7402f docs: update ChangeDetectionStrategy links (#55553)
  • f7233b0 docs: remove mention of style sanitization. (#55553)
  • f6e11e6 docs: remove image (#55553)
  • 5559b7f docs: update app-shell to reflect actual content (#55550)
  • 5b4970b refactor(platform-server): Update event_replay_spec to more match production code. (#55517)
  • 96972b4 refactor(devtools): hide hydration error when the component tree is collapsed (#54912)
  • e0096ef refactor(devtools): prevent dblclick on the expand arrow to show the element panel (#54912)
Compare

**Note:** _You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs._ For more information: šŸ§ [View latest project report](https://app.snyk.io/org/santebe/project/e15fda4c-a937-4ea7-a4e8-959d19de310c?utm_source=github&utm_medium=referral&page=upgrade-pr) šŸ›  [Adjust upgrade PR settings](https://app.snyk.io/org/santebe/project/e15fda4c-a937-4ea7-a4e8-959d19de310c/settings/integration?utm_source=github&utm_medium=referral&page=upgrade-pr) šŸ”• [Ignore this dependency or unsubscribe from future upgrade PRs](https://app.snyk.io/org/santebe/project/e15fda4c-a937-4ea7-a4e8-959d19de310c/settings/integration?pkg=zone.js&utm_source=github&utm_medium=referral&page=upgrade-pr#auto-dep-upgrades) **Note:** _This is a default PR template raised by Snyk. Find out more about how you can customise Snyk PRs in our [documentation.](https://docs.snyk.io/scan-using-snyk/snyk-open-source/automatic-and-manual-prs-with-snyk-open-source/customize-pr-templates-closed-beta)_
github-actions[bot] commented 5 months ago

This PR has been automatically marked as stale because it has not had recent activity. :calendar: It will be closed automatically in two weeks if no further activity occurs.

github-actions[bot] commented 4 months ago

This PR was closed because it has been stalled for 14 days with no activity.