Skip to content

fix(@angular-devkit/build-angular): update terser to address CVE-2022-25858#23604

Merged
clydin merged 1 commit intoangular:13.3.xfrom
alan-agius4:terser-error
Jul 20, 2022
Merged

fix(@angular-devkit/build-angular): update terser to address CVE-2022-25858#23604
clydin merged 1 commit intoangular:13.3.xfrom
alan-agius4:terser-error

Conversation

@alan-agius4
Copy link
Copy Markdown
Collaborator

While this vulnerability cannot be exploited through the Angular CLI as we don't expect it to be run on production servers. We update terser to remove the unnecessary vulnerability noise.

Closes #23593

…-25858

While this vulnerability cannot be exploited through the Angular CLI as we don't expect it to be run on production servers. We update terser to remove the unnecessary vulnerability noise.

Closes angular#23593
@alan-agius4 alan-agius4 added target: lts This PR is targeting a version currently in long-term support action: review The PR is still awaiting reviews from at least one requested reviewer labels Jul 20, 2022
@alan-agius4 alan-agius4 requested a review from clydin July 20, 2022 08:14
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Jul 20, 2022
@clydin clydin merged commit 0d62716 into angular:13.3.x Jul 20, 2022
@alan-agius4 alan-agius4 deleted the terser-error branch July 20, 2022 15:19
@angular-automatic-lock-bot
Copy link
Copy Markdown

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Aug 20, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

13.3.8 build_angular uses vulnerable terser 5.11.0: CVE-2022-25858

2 participants