-
Notifications
You must be signed in to change notification settings - Fork 12k
Angular 19 depends on vulnerable version of Vite #29996
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Closed
1 task
Labels
area: @angular/build
freq1: low
Only reported by a handful of users who observe it rarely
severity6: security
type: bug/fix
Comments
alan-agius4
added a commit
to alan-agius4/angular-cli
that referenced
this issue
Apr 2, 2025
alan-agius4
added a commit
to alan-agius4/angular-cli
that referenced
this issue
Apr 2, 2025
…curity issues Addresses GHSA-4r4m-qw57-chr8 Closes angular#29996
alan-agius4
added a commit
that referenced
this issue
Apr 2, 2025
…curity issues Addresses GHSA-4r4m-qw57-chr8 Closes #29996
alan-agius4
added a commit
that referenced
this issue
Apr 2, 2025
This was
linked to
pull requests
Apr 2, 2025
This issue has been automatically locked due to inactivity. Read more about our automatic conversation locking policy. This action has been performed automatically by a bot. |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
area: @angular/build
freq1: low
Only reported by a handful of users who observe it rarely
severity6: security
type: bug/fix
Command
other
Is this a regression?
The previous version in which this bug was not present was
No response
Description
The Angular CLI v19 depends on Vite version 6.2.3, which is vulnerable: GHSA-4r4m-qw57-chr8
It should be updated to v6.2.4
Minimal Reproduction
Generate a new error with ng new and run npm audit
Exception or Error
Your Environment
Anything else relevant?
No response
The text was updated successfully, but these errors were encountered: