Skip to content

Commit 0d62716

Browse files
alan-agius4clydin
authored andcommittedJul 20, 2022
fix(@angular-devkit/build-angular): update terser to address CVE-2022-25858
While this vulnerability cannot be exploited through the Angular CLI as we don't expect it to be run on production servers. We update terser to remove the unnecessary vulnerability noise. Closes #23593
1 parent 0bb875d commit 0d62716

File tree

3 files changed

+29
-7
lines changed

3 files changed

+29
-7
lines changed
 

‎package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -210,7 +210,7 @@
210210
"symbol-observable": "4.0.0",
211211
"tar": "^6.1.6",
212212
"temp": "^0.9.0",
213-
"terser": "5.11.0",
213+
"terser": "5.14.2",
214214
"text-table": "0.2.0",
215215
"tree-kill": "1.2.2",
216216
"ts-node": "^10.0.0",

‎packages/angular_devkit/build_angular/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -61,7 +61,7 @@
6161
"source-map-support": "0.5.21",
6262
"stylus": "0.56.0",
6363
"stylus-loader": "6.2.0",
64-
"terser": "5.11.0",
64+
"terser": "5.14.2",
6565
"text-table": "0.2.0",
6666
"tree-kill": "1.2.2",
6767
"tslib": "2.3.1",

‎yarn.lock

+27-5
Original file line numberDiff line numberDiff line change
@@ -1503,6 +1503,15 @@
15031503
"@jridgewell/set-array" "^1.0.0"
15041504
"@jridgewell/sourcemap-codec" "^1.4.10"
15051505

1506+
"@jridgewell/gen-mapping@^0.3.0":
1507+
version "0.3.2"
1508+
resolved "https://registry.yarnpkg.com/@jridgewell/gen-mapping/-/gen-mapping-0.3.2.tgz#c1aedc61e853f2bb9f5dfe6d4442d3b565b253b9"
1509+
integrity sha512-mh65xKQAzI6iBcFzwv28KVWSmCkdRBWoOh+bYQGW3+6OZvbbN3TqMGo5hqYxQniRcH9F2VZIoJCm4pa3BPDK/A==
1510+
dependencies:
1511+
"@jridgewell/set-array" "^1.0.1"
1512+
"@jridgewell/sourcemap-codec" "^1.4.10"
1513+
"@jridgewell/trace-mapping" "^0.3.9"
1514+
15061515
"@jridgewell/resolve-uri@^3.0.3":
15071516
version "3.0.3"
15081517
resolved "https://registry.yarnpkg.com/@jridgewell/resolve-uri/-/resolve-uri-3.0.3.tgz#b80093f4edbb5490c49746231513669c8f518acb"
@@ -1513,6 +1522,19 @@
15131522
resolved "https://registry.yarnpkg.com/@jridgewell/set-array/-/set-array-1.1.0.tgz#1179863356ac8fbea64a5a4bcde93a4871012c01"
15141523
integrity sha512-SfJxIxNVYLTsKwzB3MoOQ1yxf4w/E6MdkvTgrgAt1bfxjSrLUoHMKrDOykwN14q65waezZIdqDneUIPh4/sKxg==
15151524

1525+
"@jridgewell/set-array@^1.0.1":
1526+
version "1.1.2"
1527+
resolved "https://registry.yarnpkg.com/@jridgewell/set-array/-/set-array-1.1.2.tgz#7c6cf998d6d20b914c0a55a91ae928ff25965e72"
1528+
integrity sha512-xnkseuNADM0gt2bs+BvhO0p78Mk762YnZdsuzFV018NoG1Sj1SCQvpSqa7XUaTam5vAGasABV9qXASMKnFMwMw==
1529+
1530+
"@jridgewell/source-map@^0.3.2":
1531+
version "0.3.2"
1532+
resolved "https://registry.yarnpkg.com/@jridgewell/source-map/-/source-map-0.3.2.tgz#f45351aaed4527a298512ec72f81040c998580fb"
1533+
integrity sha512-m7O9o2uR8k2ObDysZYzdfhb08VuEml5oWGiosa1VdaPZ/A6QyPkAJuwN0Q1lhULOf6B7MtQmHENS743hWtCrgw==
1534+
dependencies:
1535+
"@jridgewell/gen-mapping" "^0.3.0"
1536+
"@jridgewell/trace-mapping" "^0.3.9"
1537+
15161538
"@jridgewell/sourcemap-codec@^1.4.10":
15171539
version "1.4.11"
15181540
resolved "https://registry.yarnpkg.com/@jridgewell/sourcemap-codec/-/sourcemap-codec-1.4.11.tgz#771a1d8d744eeb71b6adb35808e1a6c7b9b8c8ec"
@@ -10681,14 +10703,14 @@ terser@5.10.0, terser@^5.7.2:
1068110703
source-map "~0.7.2"
1068210704
source-map-support "~0.5.20"
1068310705

10684-
terser@5.11.0:
10685-
version "5.11.0"
10686-
resolved "https://registry.yarnpkg.com/terser/-/terser-5.11.0.tgz#2da5506c02e12cd8799947f30ce9c5b760be000f"
10687-
integrity sha512-uCA9DLanzzWSsN1UirKwylhhRz3aKPInlfmpGfw8VN6jHsAtu8HJtIpeeHHK23rxnE/cDc+yvmq5wqkIC6Kn0A==
10706+
terser@5.14.2:
10707+
version "5.14.2"
10708+
resolved "https://registry.yarnpkg.com/terser/-/terser-5.14.2.tgz#9ac9f22b06994d736174f4091aa368db896f1c10"
10709+
integrity sha512-oL0rGeM/WFQCUd0y2QrWxYnq7tfSuKBiqTjRPWrRgB46WD/kiwHwF8T23z78H6Q6kGCuuHcPB+KULHRdxvVGQA==
1068810710
dependencies:
10711+
"@jridgewell/source-map" "^0.3.2"
1068910712
acorn "^8.5.0"
1069010713
commander "^2.20.0"
10691-
source-map "~0.7.2"
1069210714
source-map-support "~0.5.20"
1069310715

1069410716
test-exclude@^6.0.0:

0 commit comments

Comments
 (0)
Please sign in to comment.