[Snyk] Fix for 4 vulnerabilities - #181
Conversation
…nerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18313044 - https://snyk.io/vuln/SNYK-JS-JSYAML-18313070 - https://snyk.io/vuln/SNYK-JS-POSTCSS-18313036 - https://snyk.io/vuln/SNYK-JS-POSTCSS-18313038
|
This is a massive upgrade across 10 major versions of Angular and a deprecated package, representing a full framework migration rather than a simple dependency update. Significant, manual refactoring is required. 1. Angular CLI & DevKit ( This jump spans from Angular v10 to v20 and introduces a vast number of breaking changes. A direct update is not feasible; the official Angular guidance is to upgrade one major version at a time. Key breaking changes include:
2.
Recommendation: This upgrade cannot be merged directly. It requires a dedicated migration project. Developers must follow the official Angular Update Guide to perform a sequential, version-by-version upgrade. This process will involve significant code refactoring, configuration changes, and testing at each step.
|
Snyk has created this PR to fix 4 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
frontend/package.jsonfrontend/package-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BRACEEXPANSION-18313044
SNYK-JS-JSYAML-18313070
SNYK-JS-POSTCSS-18313036
SNYK-JS-POSTCSS-18313038
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
🦉 Directory Traversal