Skip to content

Commit f36e38a

Browse files
clydinalan-agius4
authored andcommitted
fix(@angular/cli): update direct semver dependencies to 7.5.3
All direct usages of the `semver` package have been updated to address GHSA-c2qf-rxjj-qqgw. The `semver` package is only used as a development dependency and not included in built application code within generated projects. This update does not affect any transitive usages of `semver` and any such usages would need to be handled by relevant upstream packages.
1 parent cdb34b5 commit f36e38a

File tree

4 files changed

+10
-3
lines changed

4 files changed

+10
-3
lines changed

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -197,7 +197,7 @@
197197
"sass": "1.58.1",
198198
"sass-loader": "13.2.0",
199199
"sauce-connect-proxy": "https://saucelabs.com/downloads/sc-4.8.1-linux.tar.gz",
200-
"semver": "7.3.8",
200+
"semver": "7.5.3",
201201
"shelljs": "^0.8.5",
202202
"source-map": "0.7.4",
203203
"source-map-loader": "4.0.1",

packages/angular/cli/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
"ora": "5.4.1",
3838
"pacote": "15.1.0",
3939
"resolve": "1.22.1",
40-
"semver": "7.3.8",
40+
"semver": "7.5.3",
4141
"symbol-observable": "4.0.0",
4242
"yargs": "17.6.2"
4343
},

packages/angular_devkit/build_angular/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@
5454
"rxjs": "6.6.7",
5555
"sass": "1.58.1",
5656
"sass-loader": "13.2.0",
57-
"semver": "7.3.8",
57+
"semver": "7.5.3",
5858
"source-map-loader": "4.0.1",
5959
"source-map-support": "0.5.21",
6060
"terser": "5.16.3",

yarn.lock

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10163,6 +10163,13 @@ semver@7.3.8, semver@^7.0.0, semver@^7.1.1, semver@^7.3.5, semver@^7.3.7, semver
1016310163
dependencies:
1016410164
lru-cache "^6.0.0"
1016510165

10166+
semver@7.5.3:
10167+
version "7.5.3"
10168+
resolved "https://registry.yarnpkg.com/semver/-/semver-7.5.3.tgz#161ce8c2c6b4b3bdca6caadc9fa3317a4c4fe88e"
10169+
integrity sha512-QBlUtyVk/5EeHbi7X0fw6liDZc7BBmEaSYn01fMU1OUYbf6GPsbTtd8WmnqbI20SeycoHSeiybkE/q1Q+qlThQ==
10170+
dependencies:
10171+
lru-cache "^6.0.0"
10172+
1016610173
semver@^6.0.0, semver@^6.1.1, semver@^6.1.2, semver@^6.3.0:
1016710174
version "6.3.0"
1016810175
resolved "https://registry.yarnpkg.com/semver/-/semver-6.3.0.tgz#ee0a64c8af5e8ceea67687b133761e1becbd1d3d"

0 commit comments

Comments
 (0)