Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade: , , , , , , , , , , angular2-qrcode, core-js, dotenv, nodemon, rxjs, rxjs-compat, zone.js #2

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

shaiqa-nadeem
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯 The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

@angular/animations
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/common
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/compiler
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/core
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/forms
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/http
from 7.0.3 to 7.2.16 | 32 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/platform-browser
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/platform-browser-dynamic
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/router
from 7.0.3 to 7.2.16 | 31 versions ahead of your current version | 5 years ago
on 2020-01-08
@angular/cdk
from 7.0.3 to 7.3.7 | 14 versions ahead of your current version | 5 years ago
on 2019-04-04
angular2-qrcode
from 2.0.1 to 2.0.3 | 2 versions ahead of your current version | 5 years ago
on 2019-04-17
core-js
from 2.5.7 to 2.6.12 | 13 versions ahead of your current version | 4 years ago
on 2020-11-25
dotenv
from 6.1.0 to 6.2.0 | 3 versions ahead of your current version | 6 years ago
on 2018-12-05
nodemon
from 1.18.6 to 1.19.4 | 10 versions ahead of your current version | 5 years ago
on 2019-10-15
rxjs
from 6.3.3 to 6.6.7 | 14 versions ahead of your current version | 3 years ago
on 2021-03-28
rxjs-compat
from 6.3.3 to 6.6.7 | 14 versions ahead of your current version | 3 years ago
on 2021-03-28
zone.js
from 0.8.26 to 0.15.0 | 34 versions ahead of your current version | a month ago
on 2024-08-21

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
639 No Known Exploit
high severity Arbitrary File Overwrite
SNYK-JS-TAR-174125
639 Proof of Concept
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
639 Proof of Concept
critical severity Malicious Package
SNYK-JS-FLATMAPSTREAM-72637
639 Mature
critical severity Malicious Package
SNYK-JS-EVENTSTREAM-72638
639 Mature
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
639 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
639 Proof of Concept
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
639 Proof of Concept
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
639 No Known Exploit
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
639 No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
639 No Known Exploit
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
639 No Known Exploit
medium severity Time of Check Time of Use (TOCTOU)
npm:chownr:20180731
639 No Known Exploit
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
639 Proof of Concept
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
639 No Known Exploit
Release notes
Package name: @angular/animations
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/animations GitHub release notes
Package name: @angular/common
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/common GitHub release notes
Package name: @angular/compiler
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/compiler GitHub release notes
Package name: @angular/core
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/core GitHub release notes
Package name: @angular/forms
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/forms GitHub release notes
Package name: @angular/http
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0.with-local-changes - 2018-11-14
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/http GitHub release notes
Package name: @angular/platform-browser
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/platform-browser GitHub release notes
Package name: @angular/platform-browser-dynamic
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/platform-browser-dynamic GitHub release notes
Package name: @angular/router
  • 7.2.16 - 2020-01-08
  • 7.2.15 - 2019-05-07
  • 7.2.14 - 2019-04-23
  • 7.2.13 - 2019-04-13
  • 7.2.12 - 2019-04-03
  • 7.2.11 - 2019-03-26
  • 7.2.10 - 2019-03-20
  • 7.2.9 - 2019-03-12
  • 7.2.8 - 2019-03-06
  • 7.2.7 - 2019-02-27
  • 7.2.6 - 2019-02-20
  • 7.2.5 - 2019-02-15
  • 7.2.4 - 2019-02-06
  • 7.2.3 - 2019-01-30
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-16
  • 7.2.0 - 2019-01-07
  • 7.2.0-rc.0 - 2018-12-19
  • 7.2.0-beta.2 - 2018-12-11
  • 7.2.0-beta.1 - 2018-12-06
  • 7.2.0-beta.0 - 2018-11-28
  • 7.1.4 - 2018-12-18
  • 7.1.3 - 2018-12-11
  • 7.1.2 - 2018-12-06
  • 7.1.1 - 2018-11-28
  • 7.1.0 - 2018-11-21
  • 7.1.0-rc.0 - 2018-11-14
  • 7.1.0-beta.2 - 2018-11-07
  • 7.1.0-beta.1 - 2018-10-31
  • 7.1.0-beta.0 - 2018-10-24
  • 7.0.4 - 2018-11-14
  • 7.0.3 - 2018-11-07
from @angular/router GitHub release notes
Package name: @angular/cdk
  • 7.3.7 - 2019-04-04
  • 7.3.6 - 2019-03-26
  • 7.3.5 - 2019-03-18
  • 7.3.4 - 2019-03-11
  • 7.3.3 - 2019-02-20
  • 7.3.2 - 2019-02-11
  • 7.3.1 - 2019-02-04
  • 7.3.0 - 2019-01-28
  • 7.2.2 - 2019-01-22
  • 7.2.1 - 2019-01-07
  • 7.2.0 - 2018-12-18
  • 7.1.1 - 2018-12-03
  • 7.1.0 - 2018-11-20
  • 7.0.4 - 2018-11-13
  • 7.0.3 - 2018-11-06
from @angular/cdk GitHub release notes
Package name: angular2-qrcode
  • 2.0.3 - 2019-04-17

    This release updates Qrious to version 4.0.2. This removes the dependency for cairo which was what caused the false build error to occur. This also reduces the build size. Thanks to @ Maistho for this release!

  • 2.0.2 - 2019-04-17

    2.0.2

  • 2.0.1 - 2017-04-15

    This release contains a completely new build flow so that FESM and UMD modules are generated. I've also added a simple tsd for the parts of QRious that are used in the component.

    Development-wise, this release also includes an example project made with angular-cli. This project is mainly used for testing to make sure that the component works for JIT and AOT builds until more proper tests are made.

    Thanks to all for the help and for pointing out issues with the project! Sorry for the long wait!

from angular2-qrcode GitHub release notes
Package name: core-js
  • 2.6.12 - 2020-11-25
    • Added code points / code units explicit feature detection in String#at for preventing breakage code which use obsolete String#at proposal polyfill
    • Added OPEN_SOURCE_CONTRIBUTOR detection in postinstall
    • Added Drone CI detection in postinstall
  • 2.6.11 - 2019-12-08
  • 2.6.10 - 2019-10-13
  • 2.6.9 - 2019-05-27
  • 2.6.8 - 2019-05-21
  • 2.6.7 - 2019-05-20
  • 2.6.6 - 2019-05-19
  • 2.6.5 - 2019-02-15
  • 2.6.4 - 2019-02-07
  • 2.6.3 - 2019-01-22
  • 2.6.2 - 2019-01-10
  • 2.6.1 - 2018-12-18
  • 2.6.0 - 2018-12-05
  • 2.5.7 - 2018-05-26
from core-js GitHub release notes
Package name: dotenv from dotenv GitHub release notes
Package name: nodemon from nodemon GitHub release notes
Package name: rxjs
  • 6.6.7 - 2021-03-28
  • 6.6.6 - 2021-02-25
  • 6.6.4 - 2021-02-24
  • 6.6.3 - 2020-09-06
  • 6.6.2 - 2020-07-31
  • 6.6.1 - 2020-07-31
  • 6.6.0 - 2020-07-02
  • 6.5.5 - 2020-04-03
  • 6.5.4 - 2019-12-27
  • 6.5.3 - 2019-09-03
  • 6.5.2 - 2019-05-10
  • 6.5.1 - 2019-04-23
  • 6.5.0 - 2019-04-23
  • 6.4.0 - 2019-01-30
  • 6.3.3 - 2018-09-25
from rxjs GitHub release notes
Package name: zone.js
  • 0.15.0 - 2024-08-21
  • 0.14.10 - 2024-08-05
  • 0.14.8 - 2024-07-17
  • 0.14.7 - 2024-06-06
  • 0.14.6 - 2024-05-17
  • 0.14.5 - 2024-04-30
  • 0.14.4 - 2024-02-13
  • 0.14.3 - 2024-01-09
  • 0.14.2 - 2023-11-03
  • 0.14.1 - 2023-10-26
  • 0.14.0 - 2023-09-18
  • 0.13.3 - 2023-09-12
  • 0.13.2 - 2023-09-11
  • 0.13.1 - 2023-06-12
  • 0.13.0 - 2023-03-06
  • 0.12.0 - 2022-11-07
  • 0.11.8 - 2022-08-12
  • 0.11.7 - 2022-07-21
  • 0.11.6 - 2022-06-15
  • 0.11.5 - 2022-03-03
  • 0.11.4 - 2021-02-16
  • 0.11.3 - 2020-11-04
  • 0.11.2 - 2020-10-16
  • 0.11.1 - 2020-08-19
  • 0.11.0 - 2020-08-18
  • 0.10.3 - 2020-03-17
  • 0.10.2 - 2019-08-14
  • 0.10.1 - 2019-08-02
  • 0.10.0 - 2019-07-26
  • 0.9.1 - 2019-05-03
  • 0.9.0 - 2019-03-22
  • 0.8.29 - 2019-01-22
  • 0.8.28 - 2019-01-16
  • 0.8.27 - 2019-01-11
  • 0.8.26 - 2018-04-08
from zone.js GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

[//]: # 'snyk:metadata:{"customTemplate":{"variablesUsed":[],"fieldsUsed":[]},"dependencies":[{"name":"","from":"angular/animations","to":"angular/animations"},{"name":"","from":"angular/common","to":"angular/common"},{"name":"","from":"angular/compiler","to":"angular/compiler"},{"name":"","from":"angular/core","to":"angular/core"},{"name":"","from":"angular/forms","to":"angular/forms"},{"name":"","from":"angular/http","to":"angular/http"},{"name":"","from":"angular/platform-browser","to":"angular/platform-browser"},{"name":"","from":"angular/platform-browser-dynamic","to":"angular/platform-browser-dynamic"},{"name":"","from":"angular/router","to":"angular/router"},{"name":"","from":"angular/cdk","to":"angular/cdk"},{"name":"angular2-qrcode","from":"2.0.1","to":"2.0.3"},{"name":"core-js","from":"2.5.7","to":"2.6.12"},{"name":"dotenv","from":"6.1.0","to":"6.2.0"},{"name":"nodemon","from":"1.18.6","to":"1.19.4"},{"name":"rxjs","from":"6.3.3","to":"6.6.7"},{"name":"rxjs-compat","from":"6.3.3","to":"6.6.7"},{"name":"zone.js","from":"0.8.26","to":"0.15.0"}],"env":"prod","hasFixes":true,"isBreakingChange":false,"isMajorUpgrade":false,"issuesToFix":[{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579155","issue_id":"SNYK-JS-TAR-1579155","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-174125","issue_id":"SNYK-JS-TAR-174125","priority_score":726,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.1","score":405},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-TAR-6476909","issue_id":"SNYK-JS-TAR-6476909","priority_score":646,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.5","score":325},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Uncontrolled Resource Consumption ('Resource Exhaustion')"},{"exploit_maturity":"mature","id":"SNYK-JS-FLATMAPSTREAM-72637","issue_id":"SNYK-JS-FLATMAPSTREAM-72637","priority_score":990,"priority_score_factors":[{"type":"maliciousPackage","label":true,"score":125},{"type":"exploit","label":"High","score":375},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Malicious Package"},{"exploit_maturity":"mature","id":"SNYK-JS-EVENTSTREAM-72638","issue_id":"SNYK-JS-EVENTSTREAM-72638","priority_score":990,"priority_score_factors":[{"type":"maliciousPackage","label":true,"score":125},{"type":"exploit","label":"High","score":375},{"type":"cvssScore","label":"9.8","score":490},{"type":"scoreVersion","label":"v1","score":1}],"severity":"critical","title":"Malicious Package"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-SEMVER-3247795","issue_id":"SNYK-JS-SEMVER-3247795","priority_score":696,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"7.5","score":375},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Regular Expression Denial of Service (ReDoS)"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536528","issue_id":"SNYK-JS-TAR-1536528","priority_score":624,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536531","issue_id":"SNYK-JS-TAR-1536531","priority_score":624,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.2","score":410},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Overwrite"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579147","issue_id":"SNYK-JS-TAR-1579147","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1579152","issue_id":"SNYK-JS-TAR-1579152","priority_score":639,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"8.5","score":425},{"type":"scoreVersion","label":"v1","score":1}],"severity":"high","title":"Arbitrary File Write"},{"exploit_maturity":"no-known-exploit","id":"npm:chownr:20180731","issue_id":"npm:chownr:20180731","priority_score":434,"priority_score_factors":[{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"4.4","score":220},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Time of Check Time of Use (TOCTOU)"},{"exploit_maturity":"proof-of-concept","id":"SNYK-JS-INFLIGHT-6095116","issue_id":"SNYK-JS-INFLIGHT-6095116","priority_score":631,"priority_score_factors":[{"type":"exploit","label":"Proof of Concept","score":107},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"6.2","score":310},{"type":"scoreVersion","label":"v1","score":1}],"severity":"medium","title":"Missing Release of Resource after Effective Lifetime"},{"exploit_maturity":"no-known-exploit","id":"SNYK-JS-TAR-1536758","issue_id":"SNYK-JS-TAR-1536758","priority_score":410,"priority_score_factors":[{"type":"exploit","label":"Unproven","score":11},{"type":"fixability","label":true,"score":214},{"type":"cvssScore","label":"3.7","score":185},{"type":"scoreVersion","label":"v1","score":1}],"severity":"low","title":"Regular Expression Denial of Service (ReDoS)"}],"prId":"60349202-4ad5-4a9e-9e1f-cc7d4dc6545b","prPublicId":"60349202-4ad5-4a9e-9e1f-cc7d4dc6545b","packageManager":"npm","priorityScoreList":[639,726,646,990,990,696,624,624,639,639,434,631,410],"projectPublicId":"ba93c4e4-040f-42f8-8df7-24938d2cf775","projectUrl":"https://app.snyk.io/org/shaiqa-nadeem/project/ba93c4e4-040f-42f8-8df7-24938d2cf775?utm_source=github&utm_medium=referral&page=upgrade-pr","prType":"upgrade","templateFieldSources":{"branchName":"default","commitMessage":"default","description":"default","title":"default"},"templateVariants":["priorityScore"],"type":"auto","upgrade":["SNYK-JS-TAR-1579155","SNYK-JS-TAR-174125","SNYK-JS-TAR-6476909","SNYK-JS-FLATMAPSTREAM-72637","SNYK-JS-EVENTSTREAM-72638","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-TAR-1536528","SNYK-JS-TAR-1536531","SNYK-JS-TAR-1579147","SNYK-JS-TAR-1579152","npm:chownr:20180731","SNYK-JS-INFLIGHT-6095116","SNYK-JS-TAR-1536758"],"upgradeInfo":{"versionsDiff":31,"publishedDate":"2020-01-08T20:32:20.746Z"},"vulns":["SNYK-JS-TAR-1579155","SNYK-JS-TAR-174125","SNYK-JS-TAR-6476909","SNYK-JS-FLATMAPSTREAM-72637","SNYK-JS-EVENTSTREAM-72638","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-SEMVER-3247795","SNYK-JS-TAR-1536528","SNYK-JS-TAR-1536531","SNYK-JS-TAR-1579147","SNYK-JS-TAR-1579152","npm:chownr:20180731","SNYK-JS-INFLIGHT-6095116","SNYK-JS-TAR-1536758"]}'

Snyk has created this PR to upgrade:
  - @angular/animations from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/animations
  - @angular/common from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/common
  - @angular/compiler from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/compiler
  - @angular/core from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/core
  - @angular/forms from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/forms
  - @angular/http from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/http
  - @angular/platform-browser from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/platform-browser
  - @angular/platform-browser-dynamic from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/platform-browser-dynamic
  - @angular/router from 7.0.3 to 7.2.16.
    See this package in npm: https://www.npmjs.com/package/@angular/router
  - @angular/cdk from 7.0.3 to 7.3.7.
    See this package in npm: https://www.npmjs.com/package/@angular/cdk
  - angular2-qrcode from 2.0.1 to 2.0.3.
    See this package in npm: https://www.npmjs.com/package/angular2-qrcode
  - core-js from 2.5.7 to 2.6.12.
    See this package in npm: https://www.npmjs.com/package/core-js
  - dotenv from 6.1.0 to 6.2.0.
    See this package in npm: https://www.npmjs.com/package/dotenv
  - nodemon from 1.18.6 to 1.19.4.
    See this package in npm: https://www.npmjs.com/package/nodemon
  - rxjs from 6.3.3 to 6.6.7.
    See this package in npm: https://www.npmjs.com/package/rxjs
  - rxjs-compat from 6.3.3 to 6.6.7.
    See this package in npm: https://www.npmjs.com/package/rxjs-compat
  - zone.js from 0.8.26 to 0.15.0.
    See this package in npm: https://www.npmjs.com/package/zone.js

See this project in Snyk:
https://app.snyk.io/org/shaiqa-nadeem/project/ba93c4e4-040f-42f8-8df7-24938d2cf775?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment