Skip to content

Commit bd396b6

Browse files
clydinalan-agius4
authored andcommitted
fix(@angular/cli): update direct semver dependencies to 7.5.3
All direct usages of the `semver` package have been updated to address GHSA-c2qf-rxjj-qqgw. The `semver` package is only used as a development dependency and not included in built application code within generated projects. This update does not affect any transitive usages of `semver` and any such usages would need to be handled by relevant upstream packages.
1 parent d177918 commit bd396b6

File tree

4 files changed

+10
-3
lines changed

4 files changed

+10
-3
lines changed

package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -200,7 +200,7 @@
200200
"sass": "1.54.4",
201201
"sass-loader": "13.0.2",
202202
"sauce-connect-proxy": "https://saucelabs.com/downloads/sc-4.8.1-linux.tar.gz",
203-
"semver": "7.3.7",
203+
"semver": "7.5.3",
204204
"shelljs": "^0.8.5",
205205
"source-map": "0.7.4",
206206
"source-map-loader": "4.0.0",

packages/angular/cli/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@
3838
"ora": "5.4.1",
3939
"pacote": "13.6.2",
4040
"resolve": "1.22.1",
41-
"semver": "7.3.7",
41+
"semver": "7.5.3",
4242
"symbol-observable": "4.0.0",
4343
"uuid": "8.3.2",
4444
"yargs": "17.5.1"

packages/angular_devkit/build_angular/package.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@
5454
"rxjs": "6.6.7",
5555
"sass": "1.54.4",
5656
"sass-loader": "13.0.2",
57-
"semver": "7.3.7",
57+
"semver": "7.5.3",
5858
"source-map-loader": "4.0.0",
5959
"source-map-support": "0.5.21",
6060
"stylus": "0.59.0",

yarn.lock

+7
Original file line numberDiff line numberDiff line change
@@ -9923,6 +9923,13 @@ semver@7.3.7, semver@^7.0.0, semver@^7.1.1, semver@^7.3.5, semver@^7.3.7, semver
99239923
dependencies:
99249924
lru-cache "^6.0.0"
99259925

9926+
semver@7.5.3:
9927+
version "7.5.3"
9928+
resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.3.tgz#161ce8c2c6b4b3bdca6caadc9fa3317a4c4fe88e"
9929+
integrity sha512-QBlUtyVk/5EeHbi7X0fw6liDZc7BBmEaSYn01fMU1OUYbf6GPsbTtd8WmnqbI20SeycoHSeiybkE/q1Q+qlThQ==
9930+
dependencies:
9931+
lru-cache "^6.0.0"
9932+
99269933
semver@^6.0.0, semver@^6.1.1, semver@^6.1.2, semver@^6.3.0:
99279934
version "6.3.0"
99289935
resolved "https://registry.yarnpkg.com/semver/-/semver-6.3.0.tgz#ee0a64c8af5e8ceea67687b133761e1becbd1d3d"

0 commit comments

Comments
 (0)