Title: [Snyk] Security upgrade webpack from 3.5.5 to 5.0.0 by one3chens · Pull Request #79 · feicc/angular-cli · GitHub
Open Graph Title: [Snyk] Security upgrade webpack from 3.5.5 to 5.0.0 by one3chens · Pull Request #79 · feicc/angular-cli
X Title: [Snyk] Security upgrade webpack from 3.5.5 to 5.0.0 by one3chens · Pull Request #79 · feicc/angular-cli
Description: Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable dependencies to a fixed version: package.json package-lock.json Vulnerabilities that will be fixed With an upgrade: Severity Priority Score (*) Issue Breaking Change Exploit Maturity 701/1000 Why? Recently disclosed, Has a fix available, CVSS 8.3 Improper Verification of Cryptographic Signature SNYK-JS-ELLIPTIC-8172694 Yes No Known Exploit 828/1000 Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.7 Improper Verification of Cryptographic Signature SNYK-JS-ELLIPTIC-8187303 Yes Proof of Concept (*) Note that the real score may have changed since the PR was raised. Commit messages Package name: webpack The new version differs by 250 commits. 610f368 5.0.0 5ce65c1 update examples bbe1230 Merge pull request angular#11628 from webpack/bugfix/real-content-hash 75ecff2 5.0.0-rc.6 bfc35d6 Merge pull request angular#11603 from MayaWolf/master 76e8cbd Merge pull request angular#11622 from webpack/dependabot/npm_and_yarn/types/node-13.13.25 9fd1be2 chore(deps-dev): bump @ types/node from 13.13.23 to 13.13.25 36bcfaa Merge pull request angular#11621 from webpack/bugfix/11619 9130d10 fix called variables with ProvidePlugin 3e42105 Merge pull request angular#11620 from webpack/bugfix/11617 4709719 skip connections copied to concatenated module 57b493f 5.0.0-rc.5 1658e2f Merge pull request angular#11618 from webpack/bugfix/11615 a8fb45d fixes crash in SideEffectsFlagPlugin 84b196d emit error instead of crashing when unexpected problem occurs 5573fed Merge pull request angular#11601 from Hornwitser/improve-suggested-polyfill-config 9b5cce9 Merge pull request angular#11609 from snitin315/export-types 37c495c export type RuleSetUseItem 39faf34 export type RuleSetUse e5fd246 export type RuleSetConditionAbsolute 660baad export RuleSetCondition types 13e3ca5 Merge pull request angular#11602 from webpack/bugfix/shared-runtime-chunk 9c0587e Merge pull request angular#11606 from webpack/dependabot/npm_and_yarn/simple-git-2.21.0 502d166 Merge pull request angular#11607 from webpack/dependabot/npm_and_yarn/acorn-8.0.4 See the full diff Check the changes in this PR to ensure they won't cause issues with your project. Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs. For more information: 🧐 View latest project report 🛠 Adjust project settings 📚 Read more about Snyk's upgrade and patch logic Learn how to fix vulnerabilities with free interactive lessons: 🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.
Open Graph Description: Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable depe...
X Description: Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable depe...
Opengraph URL: https://github.com/feicc/angular-cli/pull/79
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /:user_id/:repository/pull/:id/checks(.:format) |
| route-controller | pull_requests |
| route-action | checks |
| fetch-nonce | v2:7a5d52e1-0c7c-6250-f928-d49fb372c413 |
| current-catalog-service-hash | 87dc3bc62d9b466312751bfd5f889726f4f1337bdff4e8be7da7c93d6c00a25a |
| request-id | DA8A:1C7DFD:AC8E5DC:DF5AE9E:697675D3 |
| html-safe-nonce | e7da163f0728408b17c39f51a116d23921b7e29dd209ec200710cbe65a0b8170 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJEQThBOjFDN0RGRDpBQzhFNURDOkRGNUFFOUU6Njk3Njc1RDMiLCJ2aXNpdG9yX2lkIjoiNTMwMzI2NDUyNzUzMTgwMDAyMCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 94bb5fa971e36a312c5d172e6bad120cef31ca27281cc50388921229d475953a |
| hovercard-subject-tag | pull_request:2126846776 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,checks,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/feicc/angular-cli/pull/79/checks |
| twitter:image | https://avatars.githubusercontent.com/u/7861351?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/7861351?s=400&v=4 |
| og:image:alt | Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project. Changes included in this PR Changes to the following files to upgrade the vulnerable depe... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 032152924a283b83384255d9489e7b93b54ba01da8d380b05ecd3953b3212411 |
| turbo-cache-control | no-preview |
| go-import | github.com/feicc/angular-cli git https://github.com/feicc/angular-cli.git |
| octolytics-dimension-user_id | 31312357 |
| octolytics-dimension-user_login | feicc |
| octolytics-dimension-repository_id | 101761014 |
| octolytics-dimension-repository_nwo | feicc/angular-cli |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | true |
| octolytics-dimension-repository_parent_id | 36891867 |
| octolytics-dimension-repository_parent_nwo | angular/angular-cli |
| octolytics-dimension-repository_network_root_id | 36891867 |
| octolytics-dimension-repository_network_root_nwo | angular/angular-cli |
| turbo-body-classes | logged-out env-production page-responsive full-width full-width-p-0 |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 5b577f6be6482e336e3c30e8daefa30144947b17 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width