Skip to content

Commit 3475e02

Browse files
committed
fix(@angular/cli): update direct semver dependencies to 7.5.3
All direct usages of the `semver` package have been updated to address GHSA-c2qf-rxjj-qqgw. The `semver` package is only used as a development dependency and not included in built application code within generated projects. This update does not affect any transitive usages of `semver` and any such usages would need to be handled by relevant upstream packages.
1 parent 8108b8c commit 3475e02

File tree

4 files changed

+12
-18
lines changed

4 files changed

+12
-18
lines changed

package.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -109,7 +109,7 @@
109109
"@types/picomatch": "^2.3.0",
110110
"@types/progress": "^2.0.3",
111111
"@types/resolve": "^1.17.1",
112-
"@types/semver": "^7.3.12",
112+
"@types/semver": "^7.5.0",
113113
"@types/shelljs": "^0.8.11",
114114
"@types/tar": "^6.1.2",
115115
"@types/text-table": "^0.2.1",
@@ -189,7 +189,7 @@
189189
"sass": "1.63.2",
190190
"sass-loader": "13.3.1",
191191
"sauce-connect-proxy": "https://saucelabs.com/downloads/sc-4.8.1-linux.tar.gz",
192-
"semver": "7.5.1",
192+
"semver": "7.5.3",
193193
"shelljs": "^0.8.5",
194194
"source-map": "0.7.4",
195195
"source-map-loader": "4.0.1",

packages/angular/cli/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
"ora": "5.4.1",
3838
"pacote": "15.2.0",
3939
"resolve": "1.22.2",
40-
"semver": "7.5.1",
40+
"semver": "7.5.3",
4141
"symbol-observable": "4.0.0",
4242
"yargs": "17.7.2"
4343
},

packages/angular_devkit/build_angular/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@
5757
"rxjs": "7.8.1",
5858
"sass": "1.63.2",
5959
"sass-loader": "13.3.1",
60-
"semver": "7.5.1",
60+
"semver": "7.5.3",
6161
"source-map-loader": "4.0.1",
6262
"source-map-support": "0.5.21",
6363
"terser": "5.17.7",

yarn.lock

Lines changed: 8 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -4015,7 +4015,7 @@
40154015
dependencies:
40164016
"@types/ws" "*"
40174017

4018-
"@types/semver@^7.3.12":
4018+
"@types/semver@^7.3.12", "@types/semver@^7.5.0":
40194019
version "7.5.0"
40204020
resolved "https://registry.yarnpkg.com/@types/semver/-/semver-7.5.0.tgz#591c1ce3a702c45ee15f47a42ade72c2fd78978a"
40214021
integrity sha512-G8hZ6XJiHnuhQKR7ZmysCeJWE08o8T0AXtk5darsCaTVsYZhhgUrq53jizaR2FvsoeCwJhlmwTjkXBY5Pn/ZHw==
@@ -5843,19 +5843,6 @@ critters@0.0.16:
58435843
postcss "^8.3.7"
58445844
pretty-bytes "^5.3.0"
58455845

5846-
critters@0.0.18:
5847-
version "0.0.18"
5848-
resolved "https://registry.yarnpkg.com/critters/-/critters-0.0.18.tgz#37ea730ee3a1f19844e8099c3fd75b526e1bbcc9"
5849-
integrity sha512-I7t/da29EIWXgxx2RSW1md1DvenEgEuLlki6nHE5+Nc0e3eib5AuGIGbPVuI8q+erCKkSP9T/NqYfvasAy7x7A==
5850-
dependencies:
5851-
chalk "^4.1.0"
5852-
css-select "^5.1.0"
5853-
dom-serializer "^2.0.0"
5854-
domhandler "^5.0.2"
5855-
htmlparser2 "^8.0.2"
5856-
postcss "^8.4.23"
5857-
pretty-bytes "^5.3.0"
5858-
58595846
critters@0.0.19:
58605847
version "0.0.19"
58615848
resolved "https://registry.yarnpkg.com/critters/-/critters-0.0.19.tgz#15e3a3a0ed77ae4b69c3b2fe29c8e7e87fc77d1b"
@@ -11029,6 +11016,13 @@ semver@7.5.1, semver@^7.0.0, semver@^7.1.1, semver@^7.3.5, semver@^7.3.7, semver
1102911016
dependencies:
1103011017
lru-cache "^6.0.0"
1103111018

11019+
semver@7.5.3:
11020+
version "7.5.3"
11021+
resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.3.tgz#161ce8c2c6b4b3bdca6caadc9fa3317a4c4fe88e"
11022+
integrity sha512-QBlUtyVk/5EeHbi7X0fw6liDZc7BBmEaSYn01fMU1OUYbf6GPsbTtd8WmnqbI20SeycoHSeiybkE/q1Q+qlThQ==
11023+
dependencies:
11024+
lru-cache "^6.0.0"
11025+
1103211026
semver@^6.0.0, semver@^6.1.1, semver@^6.1.2, semver@^6.3.0:
1103311027
version "6.3.0"
1103411028
resolved "https://registry.yarnpkg.com/semver/-/semver-6.3.0.tgz#ee0a64c8af5e8ceea67687b133761e1becbd1d3d"

0 commit comments

Comments
 (0)