You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
webpack-dev-middleware 6.0.0 - 6.1.1
Severity: high
Path traversal in webpack-dev-middleware - https://github.com/advisories/GHSA-wr3j-pwj9-hqq6
fix available via `npm audit fix --force`
Will install @angular-devkit/build-angular@15.0.5, which is a breaking change
node_modules/webpack-dev-middleware
@angular-devkit/build-angular 15.1.0-next.0 - 17.3.1
Depends on vulnerable versions of webpack-dev-middleware
node_modules/@angular-devkit/build-angular
joematthews
changed the title
@angular-devkit/build-angular has webpack dependency vunerability
@angular-devkit/build-angular has webpack-dev-middleware dependency vunerability
Mar 24, 2024
Tracking
npm audit
message:GHSA-wr3j-pwj9-hqq6
npm audit fix --force would downgrade @angular-devkit/build-angular to version of 15 that is not affected, which is not acceptable.
Fixes are in place and will be release soon: angular/angular-cli#27334
The text was updated successfully, but these errors were encountered: