angular-starterkit icon indicating copy to clipboard operation
angular-starterkit copied to clipboard

[Snyk] Security upgrade @nx/angular from 17.1.1 to 17.3.0

Open rickvandermey opened this issue 1 year ago • 1 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
⚠️ Warning
Failed to update the package-lock.json, please update manually before merging.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 631/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.2
Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @nx/angular The new version differs by 250 commits.
  • 7a62f41 chore(repo): update nx to 17.3.0-rc.1 (#21360)
  • e335b9f fix(release): ensure non-zero exit code is propagated, change missing target handling (#21388)
  • 9913148 chore(repo): bump the binning agents provisioning (#21398)
  • 69636ad fix(release): do not restart the daemon when skipLockFileUpdate is set (#21389)
  • c811be5 fix(core): address some wonkiness when merging command and run-commands (#21315)
  • 8274f34 fix(devkit): fix extractLayoutDirectory typescript types to better reflect allowed params and return value (#15339)
  • 2cb241a docs(linter): fix typo (#20259)
  • ec38a58 fix(js): fix missing top-level dependencies in publishable libs (#17730)
  • 1ea09ad fix(remix): tsconfigs were being incorrectly generated causing errors #21002 (#21387)
  • 911f8d6 feat(remix): add nx welcome component (#21383)
  • d08fe46 docs(vue): replace incorrect "React" in Vue doc. (#20930)
  • 5369f5d docs(release): add recipe for publishing in github actions (#21370)
  • c9f75ac fix(angular): update setup-ssr generator to support the outputPath object variant (#21385)
  • 17b09b9 fix(repo): fix version calculation on nx-release (#21382)
  • 391d226 docs(core): fix typo (#21200)
  • 1040dbd fix(core): fix conflicting types from merge conflict (#21371)
  • 1bd2e0e fix(core): fix compilerOptions may not exist (#21364)
  • 73d37cc feat(core): pass down help to run-commands (#21331)
  • 79a7e79 fix(vite): PCV3 multiple targets (#21366)
  • 00dbd14 fix(core): fix sending sigint to child tasks with the new psuedo tty … (#21369)
  • e1bb8bc fix(core): do not create new targets from target defaults when packag… (#21365)
  • b4029e0 feat(misc): hide unpublished links in project details view (#21362)
  • 4ed74a4 fix(angular): update autoprefixer migration to the right file (#21363)
  • 9c81328 fix(release): disable workspace changelogs in config when not valid (#21341)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

rickvandermey avatar Jan 31 '24 05:01 rickvandermey

Quality Gate Passed Quality Gate passed

Kudos, no new issues were introduced!

0 New issues
0 Security Hotspots
No data about Coverage
No data about Duplication

See analysis details on SonarCloud

sonarqubecloud[bot] avatar Jan 31 '24 05:01 sonarqubecloud[bot]