[Snyk] Upgrade: , , , , , , , , , , angular2-qrcode, core-js, dotenv, nodemon, rxjs, rxjs-compat, zone.js #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@angular/animations
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/common
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/compiler
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/core
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/forms
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/http
from 7.0.3 to 7.2.16 | 32 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/platform-browser
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/platform-browser-dynamic
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/router
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/cdk
from 7.0.3 to 7.3.7 | 14 versions ahead of your current version | 5 years ago
on 2019-04-04
angular2-qrcode
from 2.0.1 to 2.0.3 | 2 versions ahead of your current version | 5 years ago
on 2019-04-17
core-js
from 2.5.7 to 2.6.12 | 13 versions ahead of your current version | 4 years ago
on 2020-11-25
dotenv
from 6.1.0 to 6.2.0 | 3 versions ahead of your current version | 6 years ago
on 2018-12-05
nodemon
from 1.18.6 to 1.19.4 | 10 versions ahead of your current version | 5 years ago
on 2019-10-15
rxjs
from 6.3.3 to 6.6.7 | 14 versions ahead of your current version | 3 years ago
on 2021-03-28
rxjs-compat
from 6.3.3 to 6.6.7 | 14 versions ahead of your current version | 3 years ago
on 2021-03-28
zone.js
from 0.8.26 to 0.15.0 | 34 versions ahead of your current version | a month ago
on 2024-08-21
Issues fixed by the recommended upgrade:
SNYK-JS-TAR-1579155
SNYK-JS-TAR-174125
SNYK-JS-TAR-6476909
SNYK-JS-FLATMAPSTREAM-72637
SNYK-JS-EVENTSTREAM-72638
SNYK-JS-SEMVER-3247795
SNYK-JS-SEMVER-3247795
SNYK-JS-SEMVER-3247795
SNYK-JS-TAR-1536528
SNYK-JS-TAR-1536531
SNYK-JS-TAR-1579147
SNYK-JS-TAR-1579152
npm:chownr:20180731
SNYK-JS-INFLIGHT-6095116
SNYK-JS-TAR-1536758
Release notes
Package name: @angular/animations
Package name: @angular/common
Package name: @angular/compiler
Package name: @angular/core
Package name: @angular/forms
Package name: @angular/http
Package name: @angular/platform-browser
Package name: @angular/platform-browser-dynamic
Package name: @angular/router
Package name: @angular/cdk
Package name: angular2-qrcode
This release updates Qrious to version 4.0.2. This removes the dependency for cairo which was what caused the false build error to occur. This also reduces the build size. Thanks to @ Maistho for this release!
2.0.2
This release contains a completely new build flow so that FESM and UMD modules are generated. I've also added a simple tsd for the parts of QRious that are used in the component.
Development-wise, this release also includes an example project made with angular-cli. This project is mainly used for testing to make sure that the component works for JIT and AOT builds until more proper tests are made.
Thanks to all for the help and for pointing out issues with the project! Sorry for the long wait!
Package name: core-js
String#at
for preventing breakage code which use obsoleteString#at
proposal polyfillOPEN_SOURCE_CONTRIBUTOR
detection inpostinstall
postinstall
Package name: dotenv
6.2.0
6.1.0
Package name: nodemon
1.19.4 (2019-10-15)
Bug Fixes
jade
references bypug
(7d6c1a8), closes #15951.19.3 (2019-09-29)
Bug Fixes
1.19.2 (2019-09-03)
Bug Fixes
1.19.1 (2019-05-25)
Bug Fixes
1.19.0 (2019-05-01)
Bug Fixes
Features
1.18.11 (2019-04-08)
Bug Fixes
1.18.10 (2019-02-08)
Bug Fixes
1.18.9 (2018-12-14)
Bug Fixes
rs
in node@11 (#1493) (dd0b96a)1.18.8 (2018-12-10)
Bug Fixes
1.18.7 (2018-11-27)
Bug Fixes
Package name: rxjs
Package name: zone.js
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information:
[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"","from":"angular/animations","to":"angular/animations"},{"name":"","from":"angular/common","to":"angular/common"},{"name":"","from":"angular/compiler","to":"angular/compiler"},{"name":"","from":"angular/core","to":"angular/core"},{"name":"","from":"angular/forms","to":"angular/forms"},{"name":"","from":"angular/http","to":"angular/http"},{"name":"","from":"angular/platform-browser","to":"angular/platform-browser"},{"name":"","from":"angular/platform-browser-dynamic","to":"angular/platform-browser-dynamic"},{"name":"","from":"angular/router","to":"angular/router"},{"name":"","from":"angular/cdk","to":"angular/cdk"},{"name":"angular2-qrcode","from":"2.0.1","to":"2.0.3"},{"name":"core-js","from":"2.5.7","to":"2.6.12"},{"name":"dotenv","from":"6.1.0","to":"6.2.0"},{"name":"nodemon","from":"1.18.6","to":"1.19.4"},{"name":"rxjs","from":"6.3.3","to":"6.6.7"},{"name":"rxjs-compat","from":"6.3.3","to":"6.6.7"},{"name":"zone.js","from":"0.8.26","to":"0.15.0"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579155","issue_id":"SNYK-JS-TAR-1579155","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-174125","issue_id":"SNYK-JS-TAR-174125","priority_score":726,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.1","score":405},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-6476909","issue_id":"SNYK-JS-TAR-6476909","priority_score":646,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"mature","id":"SNYK-JS-FLATMAPSTREAM-72637","issue_id":"SNYK-JS-FLATMAPSTREAM-72637","priority_score":990,"priority_score_factors":[{"type":"maliciousPackage","label":true,"score":125},{"type":"exploit","label":"High","score":375},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Malicious Package"},{"exploit_maturity":"mature","id":"SNYK-JS-EVENTSTREAM-72638","issue_id":"SNYK-JS-EVENTSTREAM-72638","priority_score":990,"priority_score_factors":[{"type":"maliciousPackage","label":true,"score":125},{"type":"exploit","label":"High","score":375},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Malicious Package"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536528","issue_id":"SNYK-JS-TAR-1536528","priority_score":624,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536531","issue_id":"SNYK-JS-TAR-1536531","priority_score":624,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579147","issue_id":"SNYK-JS-TAR-1579147","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579152","issue_id":"SNYK-JS-TAR-1579152","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"no-known-exploit","id":"npm:chownr:20180731","issue_id":"npm:chownr:20180731","priority_score":434,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.4","score":220},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Time of Check Time of Use (TOCTOU)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-INFLIGHT-6095116","issue_id":"SNYK-JS-INFLIGHT-6095116","priority_score":631,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.2","score":310},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Missing Release of Resource after Effective Lifetime"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536758","issue_id":"SNYK-JS-TAR-1536758","priority_score":410,"priority_score_factors":[{"type":"exploit","label":"Unproven","score":11},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Regular Expression Denial of Service (ReDoS)"}],"prId":"60349202-4ad5-4a9e-9e1f-cc7d4dc6545b","prPublicId":"60349202-4ad5-4a9e-9e1f-cc7d4dc6545b","packageManager":"npm","priorityScoreList":[639,726,646,990,990,696,624,624,639,639,434,631,410],"projectPublicId":"ba93c4e4-040f-42f8-8df7-24938d2cf775","projectUrl":"https://app.snyk.io/org/shaiqa-nadeem/project/ba93c4e4-040f-42f8-8df7-24938d2cf775?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-TAR-1579155","SNYK-JS-TAR-174125","SNYK-JS-TAR-6476909","SNYK-JS-FLATMAPSTREAM-72637","SNYK-JS-EVENTSTREAM-72638","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-TAR-1536528","SNYK-JS-TAR-1536531","SNYK-JS-TAR-1579147","SNYK-JS-TAR-1579152","npm:chownr:20180731","SNYK-JS-INFLIGHT-6095116","SNYK-JS-TAR-1536758"],"upgradeInfo":{"versionsDiff":31,"publishedDate":"2020-01-08T20:32:20.746Z"},"vulns":["SNYK-JS-TAR-1579155","SNYK-JS-TAR-174125","SNYK-JS-TAR-6476909","SNYK-JS-FLATMAPSTREAM-72637","SNYK-JS-EVENTSTREAM-72638","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-TAR-1536528","SNYK-JS-TAR-1536531","SNYK-JS-TAR-1579147","SNYK-JS-TAR-1579152","npm:chownr:20180731","SNYK-JS-INFLIGHT-6095116","SNYK-JS-TAR-1536758"]}'