-
Notifications
You must be signed in to change notification settings - Fork 12k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
@angular-devkit/build-angular depends on vulnerable version of webpack - CVE-2024-43788 #28292
Comments
I see you are working on a fix; Can you give us an ETA for the release please ? :-) |
Closed via #28294 |
A release should happen later today. |
Any patch for previous Angular version, like 17? |
Any patch for previous Angular version, like 16? |
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes angular#28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes #28292
Addresses security vulnerability detailed in GHSA-4vvj-4cpr-p986. Closes #28292
Any patch for previous Angular version, like 14 ?
|
Versions prior to version 16 are no longer supported. See: https://angular.dev/reference/releases#actively-supported-versions |
Will v17 be getting the patch? |
This issue has been automatically locked due to inactivity. Read more about our automatic conversation locking policy. This action has been performed automatically by a bot. |
Command
build
Is this a regression?
The previous version in which this bug was not present was
No response
Description
Running npm_audit on an Angular v18 project outputs the following
Minimal Reproduction
Create a new angular project using the latest v18 @angular-cli
Run npm audit in the project folder
Exception or Error
No response
Your Environment
The text was updated successfully, but these errors were encountered: