-
Notifications
You must be signed in to change notification settings - Fork 12k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Angular 19 depends on vulnerable version of Vite #29936
Closed
1 task
Labels
area: @angular/build
freq1: low
Only reported by a handful of users who observe it rarely
severity6: security
type: bug/fix
Comments
alan-agius4
added a commit
to alan-agius4/angular-cli
that referenced
this issue
Mar 26, 2025
This fixes GHSA-x574-m823-4x7w Closes angular#29936
alan-agius4
added a commit
to alan-agius4/angular-cli
that referenced
this issue
Mar 26, 2025
This fixes GHSA-x574-m823-4x7w Closes angular#29936
alan-agius4
added a commit
to alan-agius4/angular-cli
that referenced
this issue
Mar 26, 2025
This was
linked to
pull requests
Mar 26, 2025
alan-agius4
added a commit
that referenced
this issue
Mar 26, 2025
alan-agius4
added a commit
that referenced
this issue
Mar 26, 2025
This fixes GHSA-x574-m823-4x7w Closes #29936
alan-agius4
added a commit
that referenced
this issue
Mar 26, 2025
This fixes GHSA-x574-m823-4x7w Closes #29936
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
area: @angular/build
freq1: low
Only reported by a handful of users who observe it rarely
severity6: security
type: bug/fix
Command
other
Is this a regression?
The previous version in which this bug was not present was
No response
Description
The Angular CLI v19 depends on Vite version 6.2.0, which is vulnerable: GHSA-x574-m823-4x7w
It should be updated to v6.2.3
Minimal Reproduction
Generate a new error with
ng new
and runnpm audit
Exception or Error
Your Environment
Anything else relevant?
No response
The text was updated successfully, but these errors were encountered: