Skip to content

Conversation

alan-agius4
Copy link
Collaborator

@alan-agius4 alan-agius4 commented Apr 9, 2025

fix(@angular-devkit/build-angular): update vite to 5.4.17

This fixes GHSA-xcj6-pq6g-qj4x

Closes #30056


fix(@angular-devkit/build-angular): remove undici from dependencies

This fixes CVE-2025-22150

Closes #30066

@alan-agius4 alan-agius4 added the target: lts This PR is targeting a version currently in long-term support label Apr 9, 2025
@alan-agius4 alan-agius4 requested a review from clydin April 9, 2025 06:27
@alan-agius4 alan-agius4 added the action: review The PR is still awaiting reviews from at least one requested reviewer label Apr 9, 2025
@angular-robot angular-robot bot added area: @angular-devkit/build-angular area: build & ci Related the build and CI infrastructure of the project labels Apr 9, 2025
@alan-agius4 alan-agius4 changed the title update undici to 6.21.1 and update vite to 5.4.17 update vite to 5.4.17 Apr 9, 2025
@alan-agius4 alan-agius4 changed the title update vite to 5.4.17 fix(@angular-devkit/build-angular): update vite to 5.4.17 Apr 9, 2025
This is needed to refresh the tokens
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Apr 9, 2025
@alan-agius4 alan-agius4 merged commit 5aa53b4 into angular:17.3.x Apr 9, 2025
31 checks passed
@alan-agius4 alan-agius4 deleted the vite-lts-17-44 branch April 9, 2025 11:20
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators May 10, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker area: @angular-devkit/build-angular area: build & ci Related the build and CI infrastructure of the project target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants