[Snyk] Fix for 18 vulnerabilities - #159
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-ESBUILD-17750822 - https://snyk.io/vuln/SNYK-JS-ANGULARSSR-15357314 - https://snyk.io/vuln/SNYK-JS-ANGULARCOMMON-18550632 - https://snyk.io/vuln/SNYK-JS-ANGULARCORE-17353317 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18313044 - https://snyk.io/vuln/SNYK-JS-PACOTE-8225084 - https://snyk.io/vuln/SNYK-JS-EXTRACTZIP-17660777 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-15789759 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-16755174 - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-17706650 - https://snyk.io/vuln/SNYK-JS-ECHARTS-16874133 - https://snyk.io/vuln/SNYK-JS-ANGULARCOMPILER-18550631 - https://snyk.io/vuln/SNYK-JS-WEBPACKDEVSERVER-17812733 - https://snyk.io/vuln/SNYK-JS-HTTPPROXYMIDDLEWARE-17375053 - https://snyk.io/vuln/SNYK-JS-ANGULARPLATFORMSERVER-16097942 - https://snyk.io/vuln/SNYK-JS-WEBPACKDEVSERVER-17812743 - https://snyk.io/vuln/SNYK-JS-BABELCORE-17342497
|
This is a massive upgrade across multiple major versions of several core dependencies, introducing significant breaking changes. Manual intervention and a careful, staged upgrade are required. 1. Angular Framework (@angular/* from v17/18 to v20/v22)This is a multi-version jump with numerous breaking changes. Key changes across these versions include:
Recommendation: A direct jump is not feasible. Follow the official Angular Update Guide (update.angular.io) to upgrade one major version at a time (17 -> 18 -> 19 -> ...). This will be a significant refactoring effort. 2. Cypress (
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
| Status | Scan Engine | Total (0) | ||||
|---|---|---|---|---|---|---|
| Open Source Security | 0 | 0 | 0 | 0 | See details |
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.
Snyk has created this PR to fix 18 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
frontend/package.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-ESBUILD-17750822
SNYK-JS-ANGULARSSR-15357314
SNYK-JS-ANGULARCOMMON-18550632
SNYK-JS-ANGULARCORE-17353317
SNYK-JS-BRACEEXPANSION-18512280
SNYK-JS-BRACEEXPANSION-18313044
SNYK-JS-PACOTE-8225084
SNYK-JS-EXTRACTZIP-17660777
SNYK-JS-BRACEEXPANSION-15789759
SNYK-JS-BRACEEXPANSION-16755174
SNYK-JS-BRACEEXPANSION-17706650
SNYK-JS-ECHARTS-16874133
SNYK-JS-ANGULARCOMPILER-18550631
SNYK-JS-WEBPACKDEVSERVER-17812733
SNYK-JS-HTTPPROXYMIDDLEWARE-17375053
SNYK-JS-ANGULARPLATFORMSERVER-16097942
SNYK-JS-WEBPACKDEVSERVER-17812743
SNYK-JS-BABELCORE-17342497
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS)
🦉 Server-side Request Forgery (SSRF)
🦉 Directory Traversal
🦉 More lessons are available in Snyk Learn