Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: @angular/animations, @angular/common, @angular/compiler, @angular/core, @angular/forms, @angular/platform-browser, @angular/platform-browser-dynamic, @angular/router #4

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

andreasnicklaus
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on
@angular/animations
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/common
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/compiler
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/core
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/forms
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/platform-browser
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/platform-browser-dynamic
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20
@angular/router
from 17.3.0 to 17.3.1
1 version ahead of your current version 25 days ago
on 2024-03-20

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
Proof of Concept
Path Traversal
SNYK-JS-WEBPACKDEVMIDDLEWARE-6476555
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
Proof of Concept
Open Redirect
SNYK-JS-EXPRESS-6474509
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
No Known Exploit
Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
Proof of Concept
Improper Access Control
SNYK-JS-VITE-6531286
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
Proof of Concept
Improper Access Control
SNYK-JS-UNDICI-6564963
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
No Known Exploit
Improper Authorization
SNYK-JS-UNDICI-6564964
763/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.4
No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: @angular/animations
  • 17.3.1 - 2024-03-20

    17.3.1 (2024-03-20)

    compiler

    Commit Description
    fix - c0788200e2 capture data bindings for content projection purposes in blocks (#54876)

    compiler-cli

    Commit Description
    fix - 99e9474aa2 symbol feature detection for the compiler (#54711)
  • 17.3.0 - 2024-03-13

    17.3.0 (2024-03-13)

    compiler

    Commit Description
    feat - 1a6beae8a2 Enable template pipeline by default. (#54571)
    fix - f386a04c9d handle two-way bindings to signal-based template variables in instruction generation (#54714)
    fix - 1f129f114e not catching for loop empty tracking expressions (#54772)

    compiler-cli

    Commit Description
    fix - 12dc4d074e account for as expression in docs extraction (#54414)
    fix - da7fbb40f0 detect when the linker is working in unpublished angular and widen supported versions (#54439)
    fix - 492e03f699 flag two-way bindings to non-signal values in templates (#54714)
    fix - 5afa4f0ec1 support ModuleWithProviders literal detection with typeof (#54650)

    core

    Commit Description
    feat - 331b16efd2 add API to inject attributes on the host node (#54604)
    feat - fb540e169a add migration for invalid two-way bindings (#54630)
    feat - c687b8f453 expose new output() API (#54650)
    feat - c809069f21 introduce outputFromObservable() interop function (#54650)
    feat - aff65fd1f4 introduce outputToObservable interop helper (#54650)
    feat - 974958913c support TypeScript 5.4 (#54414)
    fix - 39a50f9a8d ensure all initializer functions run in an injection context (#54761)
    fix - 243ccce624 exclude class attribute intended for projection matching from directive matching (#54800)
    fix - 2909e9817d prevent infinite loops in clobbered elements check (#54425)
    fix - 7243c704cf return a readonly signal on asReadonly. (#54706)
    perf - bb35414a38 speed up retrieval of DestroyRef in EventEmitter (#54748)

    http

    Commit Description
    fix - 8d37ed035c exclude caching for authenticated HTTP requests (#54746)

    router

    Commit Description
    feat - c1c7384e02 Add reusable types for router guards (#54580)
    fix - 7225485311 Navigations triggered by cancellation events should cancel previous navigation (#54710)
from @angular/animations GitHub release notes
Package name: @angular/common
  • 17.3.1 - 2024-03-20

    17.3.1 (2024-03-20)

    compiler

    Commit Description
    fix - c0788200e2 capture data bindings for content projection purposes in blocks (#54876)

    compiler-cli

    Commit Description
    fix - 99e9474aa2 symbol feature detection for the compiler (#54711)
  • 17.3.0 - 2024-03-13
    Read more
from @angular/common GitHub release notes
Package name: @angular/compiler from @angular/compiler GitHub release notes
Package name: @angular/core from @angular/core GitHub release notes
Package name: @angular/forms from @angular/forms GitHub release notes
Package name: @angular/platform-browser from @angular/platform-browser GitHub release notes
Package name: @angular/platform-browser-dynamic from @angular/platform-browser-dynamic GitHub release notes
Package name: @angular/router from @angular/router GitHub release notes
Commit messages
Package name: @angular/animations
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/common
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/compiler
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/core
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/forms
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/platform-browser
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)
  • e61ccd2 build: update to latest angular/dev-infra/github-actions/create-pr-for-changes (#54904)
  • 80e5a0a test(compiler-cli): add unit tests for `output()` JIT transform (#54841)
  • c078820 fix(compiler): capture data bindings for content projection purposes in blocks (#54876)
  • 42318e7 refactor(compiler-cli): move DelegatingPerfRecorder initialization into constructor (#54834)
  • 33dc072 build: update dependency google-closure-compiler to v20231112 (#54893)
  • 209632e build: update dependency archiver to v7 (#54892)
  • e78dd31 build: update actions/cache digest to ab5e6d0 (#54886)
  • 91029aa build: update dependency @ octokit/graphql to v8 (#54888)
  • 52296bc build: update dependency lighthouse to v11 (#54292)
  • 64862cb build: update io_bazel_rules_sass digest to 79bd239 (#54887)
  • 90bbc68 build: update cross-repo angular dependencies (#54883)
  • a5cc82e docs: update events (#54749)
  • 855b8e0 build: update dependency puppeteer-core to v22 (#54298)
  • 35e8184 build: update peter-evans/create-or-update-comment action to v4 (#54299)
  • 74506e7 build: update eslint dependencies (#50993)

Compare

Package name: @angular/platform-browser-dynamic
  • 19ec405 release: cut the v17.3.1 release
  • 99e9474 fix(compiler-cli): symbol feature detection for the compiler (#54711)
  • 766bdf3 build: update dependency google-closure-compiler to v20240317 (#54931)
  • 2a1ea5a build: update github/codeql-action action to v3.24.8 (#54932)
  • 529a5f4 refactor(docs-infra): don't rely on aio_npm in adev (#54928)
  • e70228a refactor(core): Add hydration missmatch on the component rather than the node. (#54671)
  • 4ab3a9a docs: update Angular CLI help [17.3.x] (#54911)
  • 1f5ab96 refactor(core): allow passing an environment injector while creating a view (#54903)
  • 860ecce ci: move saucelabs to regular CI job (#54926)

Snyk has created this PR to upgrade:
  - @angular/animations from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/animations
  - @angular/common from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/common
  - @angular/compiler from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/compiler
  - @angular/core from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/core
  - @angular/forms from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/forms
  - @angular/platform-browser from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/platform-browser
  - @angular/platform-browser-dynamic from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/platform-browser-dynamic
  - @angular/router from 17.3.0 to 17.3.1.
    See this package in npm: https://www.npmjs.com/package/@angular/router

See this project in Snyk:
https://app.snyk.io/org/andreasnicklaus/project/c3720acd-47a2-4bcc-8c00-397a96c483e2?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants