Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , rxjs, , core-js, material-icons, socket.io-client, zone.js #803

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

slatersnyk
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@angular-devkit/build-angular
from 0.1000.8 to 0.1102.19 | 76 versions ahead of your current version | 2 years ago
on 2022-03-31
rxjs
from 6.6.2 to 6.6.7 | 4 versions ahead of your current version | 3 years ago
on 2021-03-28
@nguniversal/express-engine
from 10.0.1 to 10.1.0 | 3 versions ahead of your current version | 4 years ago
on 2020-09-03
core-js
from 3.22.8 to 3.38.1 | 43 versions ahead of your current version | a month ago
on 2024-08-20
material-icons
from 0.3.1 to 0.7.7 | 20 versions ahead of your current version | 3 years ago
on 2021-07-22
socket.io-client
from 2.4.0 to 2.5.0 | 1 version ahead of your current version | 2 years ago
on 2022-06-26
zone.js
from 0.10.3 to 0.15.0 | 25 versions ahead of your current version | a month ago
on 2024-08-21

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIHTML-1296849
586 Proof of Concept
high severity Asymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
586 No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
586 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
586 Proof of Concept
critical severity Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962462
586 Proof of Concept
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
586 Proof of Concept
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577917
586 Proof of Concept
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577918
586 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ES5EXT-6095076
586 Proof of Concept
high severity Improper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
586 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-DECODEURICOMPONENT-3149970
586 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
586 Proof of Concept
high severity Prototype Pollution
SNYK-JS-OBJECTPATH-1017036
586 Proof of Concept
high severity Prototype Pollution
SNYK-JS-OBJECTPATH-1585658
586 No Known Exploit
medium severity Open Redirect
SNYK-JS-EXPRESS-6474509
586 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JSON5-3182856
586 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
586 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1090595
586 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SEND-7926862
586 No Known Exploit
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577916
586 Proof of Concept
medium severity Cross-site Scripting
SNYK-JS-EXPRESS-7926867
586 No Known Exploit
medium severity Prototype Pollution
SNYK-JS-OBJECTPATH-1569453
586 Proof of Concept
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
586 Proof of Concept
low severity Cross-site Scripting
SNYK-JS-SERVESTATIC-7926865
586 No Known Exploit
Release notes
Package name: @angular-devkit/build-angular
  • 0.1102.19 - 2022-03-31
  • 0.1102.18 - 2022-01-13
  • 0.1102.17 - 2021-12-16
  • 0.1102.16 - 2021-12-15
  • 0.1102.15 - 2021-10-27
  • 0.1102.14 - 2021-06-03
  • 0.1102.13 - 2021-05-12
  • 0.1102.12 - 2021-05-06
  • 0.1102.11 - 2021-04-28
  • 0.1102.10 - 2021-04-21
  • 0.1102.9 - 2021-04-14
  • 0.1102.8 - 2021-04-07
  • 0.1102.7 - 2021-04-02
  • 0.1102.6 - 2021-03-24
  • 0.1102.5 - 2021-03-17
  • 0.1102.4 - 2021-03-10
  • 0.1102.3 - 2021-03-03
  • 0.1102.2 - 2021-02-24
  • 0.1102.1 - 2021-02-17
  • 0.1102.0 - 2021-02-11
  • 0.1102.0-rc.1 - 2021-02-05
  • 0.1102.0-rc.0 - 2021-02-05
  • 0.1102.0-next.0 - 2021-01-28
  • 0.1101.4 - 2021-02-05
  • 0.1101.3 - 2021-02-05
  • 0.1101.2 - 2021-01-28
  • 0.1101.1 - 2021-01-22
  • 0.1101.0 - 2021-01-20
  • 0.1101.0-rc.0 - 2021-01-14
  • 0.1101.0-next.4 - 2021-01-06
  • 0.1101.0-next.3 - 2020-12-17
  • 0.1101.0-next.2 - 2020-12-09
  • 0.1101.0-next.1 - 2020-12-03
  • 0.1101.0-next.0 - 2020-11-18
  • 0.1100.7 - 2021-01-14
  • 0.1100.6 - 2021-01-06
  • 0.1100.5 - 2020-12-17
  • 0.1100.4 - 2020-12-09
  • 0.1100.3 - 2020-12-02
  • 0.1100.2 - 2020-11-18
  • 0.1100.1 - 2020-11-12
  • 0.1100.0 - 2020-11-11
  • 0.1100.0-rc.3 - 2020-11-10
  • 0.1100.0-rc.2 - 2020-11-05
  • 0.1100.0-rc.1 - 2020-10-28
  • 0.1100.0-rc.0 - 2020-10-22
  • 0.1100.0-next.7 - 2020-10-15
  • 0.1100.0-next.6 - 2020-10-08
  • 0.1100.0-next.5 - 2020-10-08
  • 0.1100.0-next.4 - 2020-10-01
  • 0.1100.0-next.3 - 2020-09-23
  • 0.1100.0-next.2 - 2020-09-17
  • 0.1100.0-next.1 - 2020-09-10
  • 0.1100.0-next.0 - 2020-09-02
  • 0.1002.4 - 2021-12-16
  • 0.1002.3 - 2021-02-25
  • 0.1002.2 - 2021-02-05
  • 0.1002.1 - 2020-12-17
  • 0.1002.0 - 2020-10-22
  • 0.1001.7 - 2020-10-15
  • 0.1001.6 - 2020-10-08
  • 0.1001.5 - 2020-10-08
  • 0.1001.4 - 2020-10-01
  • 0.1001.3 - 2020-09-23
  • 0.1001.2 - 2020-09-17
  • 0.1001.1 - 2020-09-10
  • 0.1001.0 - 2020-09-02
  • 0.1001.0-rc.0 - 2020-08-26
  • 0.1001.0-next.7 - 2020-08-25
  • 0.1001.0-next.6 - 2020-08-21
  • 0.1001.0-next.5 - 2020-08-13
  • 0.1001.0-next.4 - 2020-08-06
  • 0.1001.0-next.3 - 2020-07-31
  • 0.1001.0-next.2 - 2020-07-22
  • 0.1001.0-next.1 - 2020-07-15
  • 0.1001.0-next.0 - 2020-07-09
  • 0.1000.8 - 2020-08-26
from @angular-devkit/build-angular GitHub release notes
Package name: rxjs
  • 6.6.7 - 2021-03-28
  • 6.6.6 - 2021-02-25
  • 6.6.4 - 2021-02-24
  • 6.6.3 - 2020-09-06
  • 6.6.2 - 2020-07-31
from rxjs GitHub release notes
Package name: @nguniversal/express-engine
  • 10.1.0 - 2020-09-03

    commit 3f841ef
    Author: Keen Yee Liau [email protected]
    Date: Wed Sep 2 21:17:50 2020 -0700

    release: v10.1.0
    

    commit f92baae
    Author: dependabot[bot] <49699333+dependabot[bot]@ users.noreply.github.com>
    Date: Wed Sep 2 17:35:00 2020 +0000

    bl from 4.0.2 to 4.0.3.

    Signed-off-by: dependabot[bot] <[email protected]>">

    build(deps): bump bl from 4.0.2 to 4.0.3

    Bumps bl from 4.0.2 to 4.0.3.

    Signed-off-by: dependabot[bot] <[email protected]>

    commit 09ae8c0
    Author: Renovate Bot [email protected]
    Date: Wed Sep 2 16:51:20 2020 +0000

    build: update karma to version 5.2.1
    

    commit 132de1e
    Author: Keen Yee Liau [email protected]
    Date: Thu Aug 27 10:42:25 2020 -0700

    release: v10.1.0-rc.0
    

    commit 756d0b1
    Author: Alan Agius [email protected]
    Date: Thu Aug 27 10:08:22 2020 +0200

    build: update Angular packages to 10.1.0-rc.0
    

    commit 0eb7253
    Author: Alan Agius [email protected]
    Date: Wed Aug 26 10:20:21 2020 +0200

    build: update @ types/hapi__hapi to version ^20.0.0
    

    commit b8a0040
    Author: Alan Agius [email protected]
    Date: Wed Aug 26 08:23:46 2020 +0200

    build: update to TypeScript 4.0
    

    commit e47dbc8
    Author: Renovate Bot [email protected]
    Date: Sat Aug 22 05:05:28 2020 +0000

    build: update ts-node to version 9.0.0
    

    commit f3efa35
    Author: Renovate Bot [email protected]
    Date: Sat Aug 15 05:04:27 2020 +0000

    build: update rollup to version ~2.26.0
    

    commit 7bdd58d
    Author: Renovate Bot [email protected]
    Date: Fri Aug 14 05:04:39 2020 +0000

    build: update rollup to version ~2.25.0
    

    commit 1b2ddbb
    Author: Renovate Bot [email protected]
    Date: Thu Aug 13 05:05:04 2020 +0000

    build: update karma-jasmine to version 4.0.1
    

    commit d45d9b1
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Wed Aug 12 01:29:03 2020 -0400

    [email protected]>">
    build: update karma-jasmine to version 4.0.0 (#1798)

    Co-authored-by: Renovate Bot <[email protected]>




  • 10.1.0-rc.0 - 2020-08-27

    commit 132de1e

    Author: Keen Yee Liau [email protected]

    Date: Thu Aug 27 10:42:25 2020 -0700

    release: v10.1.0-rc.0
    

    commit 756d0b1
    Author: Alan Agius [email protected]
    Date: Thu Aug 27 10:08:22 2020 +0200

    build: update Angular packages to 10.1.0-rc.0
    

    commit 0eb7253
    Author: Alan Agius [email protected]
    Date: Wed Aug 26 10:20:21 2020 +0200

    build: update @ types/hapi__hapi to version ^20.0.0
    

    commit b8a0040
    Author: Alan Agius [email protected]
    Date: Wed Aug 26 08:23:46 2020 +0200

    build: update to TypeScript 4.0
    

    commit e47dbc8
    Author: Renovate Bot [email protected]
    Date: Sat Aug 22 05:05:28 2020 +0000

    build: update ts-node to version 9.0.0
    

    commit f3efa35
    Author: Renovate Bot [email protected]
    Date: Sat Aug 15 05:04:27 2020 +0000

    build: update rollup to version ~2.26.0
    

    commit 7bdd58d
    Author: Renovate Bot [email protected]
    Date: Fri Aug 14 05:04:39 2020 +0000

    build: update rollup to version ~2.25.0
    

    commit 1b2ddbb
    Author: Renovate Bot [email protected]
    Date: Thu Aug 13 05:05:04 2020 +0000

    build: update karma-jasmine to version 4.0.1
    

    commit d45d9b1
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Wed Aug 12 01:29:03 2020 -0400

    [email protected]>">
    build: update karma-jasmine to version 4.0.0 (#1798)

    Co-authored-by: Renovate Bot <[email protected]>




  • 10.0.2 - 2020-08-11

    commit 4e949a3

    Author: Keen Yee Liau [email protected]

    Date: Tue Aug 11 14:18:43 2020 -0700

    release: v10.0.2
    

    commit 34ec6be
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Mon Aug 10 12:16:47 2020 +0200

    [email protected]>">
    build: update concurrently to version 5.3.0 (#1791)

    Co-authored-by: Renovate Bot <[email protected]>

    commit b5c2eb2
    Author: An Sergei [email protected]
    Date: Sat Aug 8 03:38:10 2020 +1000

    http://api.example.com?params=1&amp;params=2&amp;params=3 cache key will be http://api.example.com?params=1
    for api http://api.example.com?params=1&amp;params=2 cache key will be the same http://api.example.com?params=1
    and therefor API request will not be sent to server.">
    fix(common): handle arrays in querystrings

    caching GET request with query string with array of parameter gets the first value only.
    it breaks caching for the same url with different query string for example
    for api http://api.example.com?params=1&amp;params=2&amp;params=3 cache key will be http://api.example.com?params=1
    for api http://api.example.com?params=1&amp;params=2 cache key will be the same http://api.example.com?params=1
    and therefor API request will not be sent to server.

    commit 7a4032a
    Author: Renovate Bot [email protected]
    Date: Sat Aug 1 12:55:23 2020 +0000

    build: update terser to version ^5.0.0
    

    commit da64943
    Author: Renovate Bot [email protected]
    Date: Sat Aug 1 05:04:50 2020 +0000

    build: update tslint to version 6.1.3
    

    commit adb8965
    Author: Alan Agius [email protected]
    Date: Fri Jul 31 20:02:00 2020 +0200

    docs: fix bug template

    The bug template is not showing

    commit 06b5113
    Author: Renovate Bot [email protected]
    Date: Wed Jul 29 05:04:49 2020 +0000

    build: update karma to version 5.1.1
    

    commit c57bd3f
    Author: Renovate Bot [email protected]
    Date: Fri Jul 24 05:04:28 2020 +0000

    build: update rollup to version ~2.23.0
    

    commit e158998
    Author: Renovate Bot [email protected]
    Date: Fri Jul 24 05:04:10 2020 +0000

    build: update jasmine-core to version 3.6.0
    

    commit 5e14b93
    Author: Renovate Bot [email protected]
    Date: Mon Jul 20 07:42:26 2020 +0000

    build: update to version
    

    commit df1881a
    Author: Renovate Bot [email protected]
    Date: Sat Jul 18 12:54:36 2020 +0000

    build: update rollup to version ~2.22.0
    

    commit ef4e27d
    Author: Renovate Bot [email protected]
    Date: Sat Jul 18 05:05:57 2020 +0000

    build: update puppeteer to version ~5.2.0
    

    commit c7a4cdf
    Author: Renovate Bot [email protected]
    Date: Thu Jul 16 21:47:03 2020 +0000

    build: update to version
    

    commit b31a26b
    Author: Renovate Bot [email protected]
    Date: Mon Jul 13 08:55:21 2020 +0000

    build: update puppeteer to version ~5.1.0
    

    commit eadf4d4
    Author: Alan Agius [email protected]
    Date: Wed Jul 8 16:34:48 2020 +0200

    https://github.com/angular/angular/blob/fd65958b887f6ea8dd5235e6de1d533e4c578602/packages/bazel/src/ng_package/ng_package.bzl#L226-L228

    Users using UMD bundles, shouldn't be needing to add the tslib script, also this is important because tslib is a direct depedency of the package and not a peer depedency.

    This is also to align with the Angular FW packages.">

    build: embed tslib in umd bundles (#1760)

    When tslib is listed as part of the globals, it will not be embedded in the UMD bundles.
    https://github.com/angular/angular/blob/fd65958b887f6ea8dd5235e6de1d533e4c578602/packages/bazel/src/ng_package/ng_package.bzl#L226-L228

    Users using UMD bundles, shouldn't be needing to add the tslib script, also this is important because tslib is a direct depedency of the package and not a peer depedency.

    This is also to align with the Angular FW packages.

    commit 9e0a150
    Author: Renovate Bot [email protected]
    Date: Wed Jul 8 05:07:47 2020 +0000

    build: update rollup to version ~2.21.0
    

    commit 2aab22f
    Author: Adam Plumer [email protected]
    Date: Sat Jun 27 16:17:36 2020 -0500

    fixup! docs: update issue template and Gotchas guide
    

    commit cc6f717
    Author: Adam Plumer [email protected]
    Date: Sat Jun 27 16:16:29 2020 -0500

    fixup! docs: update issue template and Gotchas guide
    

    commit 394f30f
    Author: Adam Plumer [email protected]
    Date: Sat Jun 13 22:34:22 2020 -0500

    docs: update issue template and Gotchas guide

    The Gotchas guide hasn't been updated in quite some time. This
    refresh adds a more structured layout with explicit examples
    and solutions for the most common issues.

    This also updates the issue template to add a note about what
    constitutes an appropriate issue, and a link to the gotchas guide.

    commit 6fc561b
    Author: Renovate Bot [email protected]
    Date: Tue Jul 7 05:06:10 2020 +0000

    build: update rollup to version ~2.20.0
    

    commit 6be1af9
    Author: Renovate Bot [email protected]
    Date: Mon Jul 6 07:42:30 2020 +0000

    build: update to version
    

    commit 7a4e603
    Author: Renovate Bot [email protected]
    Date: Sun Jul 5 05:31:05 2020 +0000

    build: update rollup to version ~2.19.0
    

    commit fd444a1
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Fri Jul 3 01:27:01 2020 -0500

    [email protected]>">
    build: update to version (#1717)

    Co-authored-by: Renovate Bot <[email protected]>

    commit dc2b87c
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Fri Jul 3 01:04:56 2020 -0500

    [email protected]>">
    build: update codelyzer to version 6.0.0 (#1752)

    Co-authored-by: Renovate Bot <[email protected]>

    commit 61c7e3d
    Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
    Date: Fri Jul 3 00:47:20 2020 -0500

    [email protected]>">
    build: update puppeteer to version ~5.0.0 (#1753)

    Co-authored-by: Renovate Bot <[email protected]>




  • 10.0.1 - 2020-06-30

    commit 8a32f27

    Author: Keen Yee Liau [email protected]

    Date: Tue Jun 30 13:57:38 2020 -0700

    release: v10.0.1
    

    commit c262c72
    Author: Alan Agius [email protected]
    Date: Fri Jun 26 13:00:45 2020 +0200

    build: update lock file and @ types/node resolutions
    

    commit 2dbe674
    Author: Alan Agius [email protected]
    Date: Fri Jun 26 10:52:35 2020 +0200

    fix(express-engine): RenderOptions is not assignable to object

    Closes #1744

    commit 0ebf846
    Author: Alan Agius [email protected]
    Date: Fri Jun 26 10:45:56 2020 +0200

    fix(express-engine): fix return type for app method
    

    commit 9024f1c
    Author: Alan Agius [email protected]
    Date: Fri Jun 26 10:41:24 2020 +0200

    test: enable strict mode testing
    

    commit ea49db1
    Author: Alan Agius [email protected]
    Date: Thu Jun 25 12:14:20 2020 +0200

    tests: update tests to work with version 10
    
from @nguniversal/express-engine GitHub release notes
Package name: core-js

Snyk has created this PR to upgrade:
  - @angular-devkit/build-angular from 0.1000.8 to 0.1102.19.
    See this package in npm: https://www.npmjs.com/package/@angular-devkit/build-angular
  - rxjs from 6.6.2 to 6.6.7.
    See this package in npm: https://www.npmjs.com/package/rxjs
  - @nguniversal/express-engine from 10.0.1 to 10.1.0.
    See this package in npm: https://www.npmjs.com/package/@nguniversal/express-engine
  - core-js from 3.22.8 to 3.38.1.
    See this package in npm: https://www.npmjs.com/package/core-js
  - material-icons from 0.3.1 to 0.7.7.
    See this package in npm: https://www.npmjs.com/package/material-icons
  - socket.io-client from 2.4.0 to 2.5.0.
    See this package in npm: https://www.npmjs.com/package/socket.io-client
  - zone.js from 0.10.3 to 0.15.0.
    See this package in npm: https://www.npmjs.com/package/zone.js

See this project in Snyk:
https://app.snyk.io/org/victoria.slater/project/ff20ccbf-1f3e-4a45-9798-6831b54191be?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants