[Snyk] Upgrade: , rxjs, , core-js, material-icons, socket.io-client, zone.js #789
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@angular-devkit/build-angular
from 0.1000.8 to 0.1102.19 | 76 versions ahead of your current version | 2 years ago
on 2022-03-31
rxjs
from 6.6.2 to 6.6.7 | 4 versions ahead of your current version | 3 years ago
on 2021-03-28
@nguniversal/express-engine
from 10.0.1 to 10.1.0 | 3 versions ahead of your current version | 4 years ago
on 2020-09-03
core-js
from 3.22.8 to 3.38.0 | 42 versions ahead of your current version | a month ago
on 2024-08-04
material-icons
from 0.3.1 to 0.7.7 | 20 versions ahead of your current version | 3 years ago
on 2021-07-22
socket.io-client
from 2.4.0 to 2.5.0 | 1 version ahead of your current version | 2 years ago
on 2022-06-26
zone.js
from 0.10.3 to 0.14.10 | 24 versions ahead of your current version | a month ago
on 2024-08-05
Issues fixed by the recommended upgrade:
SNYK-JS-ELLIPTIC-7577918
SNYK-JS-ES5EXT-6095076
SNYK-JS-ANSIHTML-1296849
SNYK-JS-BROWSERIFYSIGN-6037026
SNYK-JS-DECODEURICOMPONENT-3149970
SNYK-JS-NTHCHECK-1586032
SNYK-JS-OBJECTPATH-1017036
SNYK-JS-OBJECTPATH-1585658
SNYK-JS-EXPRESS-6474509
SNYK-JS-BABELTRAVERSE-5962462
SNYK-JS-JSON5-3182856
SNYK-JS-JSON5-3182856
SNYK-JS-ELLIPTIC-7577916
SNYK-JS-ELLIPTIC-7577917
SNYK-JS-OBJECTPATH-1569453
SNYK-JS-POSTCSS-1090595
SNYK-JS-POSTCSS-1255640
SNYK-JS-POSTCSS-1090595
SNYK-JS-POSTCSS-1255640
Release notes
Package name: @angular-devkit/build-angular
Package name: rxjs
Package name: @nguniversal/express-engine
commit 3f841ef
Author: Keen Yee Liau kyliau@google.com
Date: Wed Sep 2 21:17:50 2020 -0700
commit f92baae
Author: dependabot[bot] <49699333+dependabot[bot]@ users.noreply.github.com>
Date: Wed Sep 2 17:35:00 2020 +0000
Signed-off-by: dependabot[bot] <support@github.com>">
commit 09ae8c0
Author: Renovate Bot bot@renovateapp.com
Date: Wed Sep 2 16:51:20 2020 +0000
commit 132de1e
Author: Keen Yee Liau kyliau@google.com
Date: Thu Aug 27 10:42:25 2020 -0700
commit 756d0b1
Author: Alan Agius alan.agius4@gmail.com
Date: Thu Aug 27 10:08:22 2020 +0200
commit 0eb7253
Author: Alan Agius alan.agius4@gmail.com
Date: Wed Aug 26 10:20:21 2020 +0200
commit b8a0040
Author: Alan Agius alan.agius4@gmail.com
Date: Wed Aug 26 08:23:46 2020 +0200
commit e47dbc8
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 22 05:05:28 2020 +0000
commit f3efa35
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 15 05:04:27 2020 +0000
commit 7bdd58d
Author: Renovate Bot bot@renovateapp.com
Date: Fri Aug 14 05:04:39 2020 +0000
commit 1b2ddbb
Author: Renovate Bot bot@renovateapp.com
Date: Thu Aug 13 05:05:04 2020 +0000
commit d45d9b1
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Wed Aug 12 01:29:03 2020 -0400
10.1.0-rc.0 - 2020-08-27
commit 132de1e
Author: Keen Yee Liau kyliau@google.com
Date: Thu Aug 27 10:42:25 2020 -0700
commit 756d0b1
Author: Alan Agius alan.agius4@gmail.com
Date: Thu Aug 27 10:08:22 2020 +0200
commit 0eb7253
Author: Alan Agius alan.agius4@gmail.com
Date: Wed Aug 26 10:20:21 2020 +0200
commit b8a0040
Author: Alan Agius alan.agius4@gmail.com
Date: Wed Aug 26 08:23:46 2020 +0200
commit e47dbc8
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 22 05:05:28 2020 +0000
commit f3efa35
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 15 05:04:27 2020 +0000
commit 7bdd58d
Author: Renovate Bot bot@renovateapp.com
Date: Fri Aug 14 05:04:39 2020 +0000
commit 1b2ddbb
Author: Renovate Bot bot@renovateapp.com
Date: Thu Aug 13 05:05:04 2020 +0000
commit d45d9b1
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Wed Aug 12 01:29:03 2020 -0400
10.0.2 - 2020-08-11
commit 4e949a3
Author: Keen Yee Liau kyliau@google.com
Date: Tue Aug 11 14:18:43 2020 -0700
commit 34ec6be
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Mon Aug 10 12:16:47 2020 +0200
commit b5c2eb2
Author: An Sergei ahn.sergei@gmail.com
Date: Sat Aug 8 03:38:10 2020 +1000
for api http://api.example.com?params=1&params=2 cache key will be the same http://api.example.com?params=1
and therefor API request will not be sent to server.">
commit 7a4032a
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 1 12:55:23 2020 +0000
commit da64943
Author: Renovate Bot bot@renovateapp.com
Date: Sat Aug 1 05:04:50 2020 +0000
commit adb8965
Author: Alan Agius alan.agius4@gmail.com
Date: Fri Jul 31 20:02:00 2020 +0200
docs: fix bug template
The bug template is not showing
commit 06b5113
Author: Renovate Bot bot@renovateapp.com
Date: Wed Jul 29 05:04:49 2020 +0000
commit c57bd3f
Author: Renovate Bot bot@renovateapp.com
Date: Fri Jul 24 05:04:28 2020 +0000
commit e158998
Author: Renovate Bot bot@renovateapp.com
Date: Fri Jul 24 05:04:10 2020 +0000
commit 5e14b93
Author: Renovate Bot bot@renovateapp.com
Date: Mon Jul 20 07:42:26 2020 +0000
commit df1881a
Author: Renovate Bot bot@renovateapp.com
Date: Sat Jul 18 12:54:36 2020 +0000
commit ef4e27d
Author: Renovate Bot bot@renovateapp.com
Date: Sat Jul 18 05:05:57 2020 +0000
commit c7a4cdf
Author: Renovate Bot bot@renovateapp.com
Date: Thu Jul 16 21:47:03 2020 +0000
commit b31a26b
Author: Renovate Bot bot@renovateapp.com
Date: Mon Jul 13 08:55:21 2020 +0000
commit eadf4d4
Author: Alan Agius alan.agius4@gmail.com
Date: Wed Jul 8 16:34:48 2020 +0200
Users using UMD bundles, shouldn't be needing to add the tslib script, also this is important because tslib is a direct depedency of the package and not a peer depedency.
This is also to align with the Angular FW packages.">
commit 9e0a150
Author: Renovate Bot bot@renovateapp.com
Date: Wed Jul 8 05:07:47 2020 +0000
commit 2aab22f
Author: Adam Plumer caerus.karu@gmail.com
Date: Sat Jun 27 16:17:36 2020 -0500
commit cc6f717
Author: Adam Plumer caerus.karu@gmail.com
Date: Sat Jun 27 16:16:29 2020 -0500
commit 394f30f
Author: Adam Plumer caerus.karu@gmail.com
Date: Sat Jun 13 22:34:22 2020 -0500
docs: update issue template and Gotchas guide
The Gotchas guide hasn't been updated in quite some time. This
refresh adds a more structured layout with explicit examples
and solutions for the most common issues.
This also updates the issue template to add a note about what
constitutes an appropriate issue, and a link to the gotchas guide.
commit 6fc561b
Author: Renovate Bot bot@renovateapp.com
Date: Tue Jul 7 05:06:10 2020 +0000
commit 6be1af9
Author: Renovate Bot bot@renovateapp.com
Date: Mon Jul 6 07:42:30 2020 +0000
commit 7a4e603
Author: Renovate Bot bot@renovateapp.com
Date: Sun Jul 5 05:31:05 2020 +0000
commit fd444a1
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Fri Jul 3 01:27:01 2020 -0500
commit dc2b87c
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Fri Jul 3 01:04:56 2020 -0500
commit 61c7e3d
Author: renovate[bot] <29139614+renovate[bot]@ users.noreply.github.com>
Date: Fri Jul 3 00:47:20 2020 -0500
10.0.1 - 2020-06-30
commit 8a32f27
Author: Keen Yee Liau kyliau@google.com
Date: Tue Jun 30 13:57:38 2020 -0700
commit c262c72
Author: Alan Agius alan.agius4@gmail.com
Date: Fri Jun 26 13:00:45 2020 +0200
commit 2dbe674
Author: Alan Agius alan.agius4@gmail.com
Date: Fri Jun 26 10:52:35 2020 +0200
fix(express-engine):
RenderOptions
is not assignable toobject
Closes #1744
commit 0ebf846
Author: Alan Agius alan.agius4@gmail.com
Date: Fri Jun 26 10:45:56 2020 +0200
commit 9024f1c
Author: Alan Agius alan.agius4@gmail.com
Date: Fri Jun 26 10:41:24 2020 +0200
commit ea49db1
Author: Alan Agius alan.agius4@gmail.com
Date: Thu Jun 25 12:14:20 2020 +0200
Package name: core-js
RegExp.escape
proposal:RegExp.escape
/actual/
namespace entries, unconditional forced replacement changed to feature detectionPromise.try
proposal:Promise.try
/actual/
namespace entries, unconditional forced replacement changed to feature detectionUint8Array
to / from base64 and hex stage 3 proposal:Uint8Array.fromBase64
Uint8Array.fromHex
Uint8Array.prototype.setFromBase64
Uint8Array.prototype.setFromHex
Uint8Array.prototype.toBase64
Uint8Array.prototype.toHex
Uint8Array.prototype.{ setFromBase64, setFromHex }
methodsUint8Array.fromBase64
andUint8Array.prototype.setFromBase64
lastChunkHandling
option, proposal-arraybuffer-base64/33Uint8Array.prototype.toBase64
omitPadding
option, proposal-arraybuffer-base64/60TypeError
on arrays backed by detached buffersRegExp
named capture groups polyfill in combination with non-capturing groups, #1352, thanks @ Ulopprocess.getBuiltinModule
for getting built-in NodeJS modules where it's availablehttps
instead ofhttp
inURL
constructor feature detection to avoid extra notifications from some overly vigilant security scanners, #1345browserslist
incore-js-compat
dependencies that fixes an upstream issue with incorrect interpretation of somebrowserslist
queries, #1344, browserslist/829, browserslist/836Object.groupBy
andMap.groupBy
to work for non-objectsRangeError
ifSet
methods are called on an object with negative size propertySet.prototype.symmetricDifference
to callthis.has
in each iterationArray.fromAsync
to not call theArray
constructor twiceURL.parse
Math.f16round
andDataView.prototype.{ getFloat16, setFloat16 }
marked as shipped from FF129Symbol.asyncDispose
added and marked as supported from V8 ~ Chromium 127Promise.try
added and marked as supported from V8 ~ Chromium 128self
descriptor is broken in Deno 1.45.3 (again)URL.parse
feature detection for some specific casesSet
methods proposal added and marked as supported from FF 127Symbol.dispose
added and marked as supported from V8 ~ Chromium 125Math.f16round
andDataView.prototype.{ getFloat16, setFloat16 }
added and marked as supported from Deno 1.43URL.parse
added and marked as supported from Chromium 126URL.parse
added and marked as supported from NodeJS 22.0URL.parse
added and marked as supported from Deno 1.43Set
methods proposal:Set.prototype.intersection
Set.prototype.union
Set.prototype.difference
Set.prototype.symmetricDifference
Set.prototype.isSubsetOf
Set.prototype.isSupersetOf
Set.prototype.isDisjointFrom
es.
namespace modules,/es/
and/stable/
namespaces entriesMath.sumPrecise
stage 2.7 proposal:Math.sumPrecise
Promise.try
proposal:Promise.try
RegExp.escape
stage 2 proposal:Symbol.customMatcher
Symbol.customMatcher
Symbol.customMatcher
well-known symbol from the pattern matching p...