Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm-audit angular-devkit postcss and dns-packet vulnerabilities #20943

Closed
joaopmi opened this issue May 25, 2021 · 2 comments
Closed

npm-audit angular-devkit postcss and dns-packet vulnerabilities #20943

joaopmi opened this issue May 25, 2021 · 2 comments

Comments

@joaopmi
Copy link

joaopmi commented May 25, 2021

Vulnerabilites keep showing in angular 12.0.1
@angular/cli - 12.0.1
@angular-devkit/build-angular - 12.0.1

package.json

{
  "name": "smab-ecm-angular",
  "version": "1.0.7",
  "scripts": {
    "ng": "ng",
    "start": "ng serve",
    "build": "ng build",
    "test": "ng test",
    "lint": "ng lint",
    "e2e": "ng e2e",
    "compodoc": "npx compodoc -p tsconfig.app.json src"
  },
  "private": true,
  "dependencies": {
    "@angular/animations": "~12.0.1",
    "@angular/cdk": "^12.0.1",
    "@angular/common": "~12.0.1",
    "@angular/compiler": "~12.0.1",
    "@angular/core": "~12.0.1",
    "@angular/forms": "~12.0.1",
    "@angular/material": "^12.0.1",
    "@angular/material-moment-adapter": "^12.0.1",
    "@angular/platform-browser": "~12.0.1",
    "@angular/platform-browser-dynamic": "~12.0.1",
    "@angular/router": "~12.0.1",
    "@angular/service-worker": "^12.0.1",
    "@types/crypto-js": "^4.0.1",
    "crypto-js": "^4.0.0",
    "moment": "^2.29.1",
    "roboto-fontface": "^0.10.0",
    "rxjs": "~6.6.0",
    "tsconfig-paths": "^3.9.0",
    "tslib": "^2.1.0",
    "zone.js": "~0.11.4"
  },
  "devDependencies": {
    "@angular-devkit/build-angular": "^12.0.1",
    "@angular/cli": "~12.0.1",
    "@angular/compiler-cli": "~12.0.1",
    "@types/jasmine": "~3.6.0",
    "@types/jasminewd2": "~2.0.3",
    "@types/node": "^12.20.4",
    "codelyzer": "^6.0.0",
    "jasmine-core": "~3.6.0",
    "jasmine-spec-reporter": "~5.0.0",
    "karma": "~6.3.2",
    "karma-chrome-launcher": "~3.1.0",
    "karma-coverage-istanbul-reporter": "~3.0.2",
    "karma-jasmine": "~4.0.0",
    "karma-jasmine-html-reporter": "^1.5.0",
    "protractor": "~7.0.0",
    "ts-node": "~8.3.0",
    "tslint": "~6.1.0",
    "typescript": "^4.2.4"
  }
}

Result npm-audit:

=== npm audit security report ===                        

                                                                               
                                                                               
                                Manual Review                                  
            Some vulnerabilities require your attention to resolve             
                                                                               
         Visit https://go.npm.me/audit-guide for additional guidance           
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 autoprefixer > postcss                                        
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 css-blank-pseudo > postcss                                    
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 css-has-pseudo > postcss                                      
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 css-prefers-color-scheme > postcss                            
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env > postcss  
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-attribute-case-insensitive > postcss                  
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-color-functional-notation > postcss                   
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-color-gray > postcss                                  
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-color-hex-alpha > postcss                             
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-color-mod-function > postcss                          
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-color-rebeccapurple > postcss                         
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-custom-media > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-custom-properties > postcss                           
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-custom-selectors > postcss                            
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-dir-pseudo-class > postcss                            
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-double-position-gradients > postcss                   
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-env-function > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-focus-visible > postcss                               
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-focus-within > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-font-variant > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-gap-properties > postcss                              
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-image-set-function > postcss                          
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-initial > postcss                                     
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-lab-function > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-logical > postcss                                     
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-media-minmax > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-nesting > postcss                                     
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-overflow-shorthand > postcss                          
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-page-break > postcss                                  
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-place > postcss                                       
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-pseudo-class-any-link > postcss                       
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-replace-overflow-wrap > postcss                       
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-selector-matches > postcss                            
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > postcss-preset-env >          
                 postcss-selector-not > postcss                                
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 Moderate        Regular Expression Denial of Service                          
                                                                               
 Package         postcss                                                       
                                                                               
 Patched in      >=8.2.10                                                      
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > resolve-url-loader > postcss  
                                                                               
 More info       https://npmjs.com/advisories/1693                             
                                                                               
                                                                               
 High            Memory Exposure                                               
                                                                               
 Package         dns-packet                                                    
                                                                               
 Patched in      >=5.2.2                                                       
                                                                               
 Dependency of   @angular-devkit/build-angular [dev]                           
                                                                               
 Path            @angular-devkit/build-angular > webpack-dev-server > bonjour  
                 > multicast-dns > dns-packet                                  
                                                                               
 More info       https://npmjs.com/advisories/1745                             
                                                                               
found 36 vulnerabilities (35 moderate, 1 high) in 1588 scanned packages
@clydin
Copy link
Member

clydin commented May 25, 2021

Duplicate of #20795

@clydin clydin marked this as a duplicate of #20795 May 25, 2021
@clydin clydin closed this as completed May 25, 2021
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Jun 25, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants