Skip to content

update vulnerabilities - #88

Merged
kflemin merged 1 commit into
mainfrom
vulnerability-updates
Sep 22, 2026
Merged

kflemin merged 1 commit into
mainfrom
vulnerability-updates

Conversation

@kflemin

@kflemin kflemin commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Addresses: CVE-2026-13697, CVE-2026-53486, CVE-2026-29063, CVE-2026-45623, CVE-2026-4800, CVE-2026-33228, CVE-2026-67213, CVE-2026-6734, CVE-2026-33750, CVE-2026-39364

  • Ran  pnpm update  to pull in patched versions for 9 CVEs (undici, immutable, postcss, lodash, flatted, nanoid, brace-expansion, vite) — all transitive/direct devDependencies. This bumped  @angular/build / @angular/cli  21.2.5→21.2.24,  postcss  8.5.8→8.5.28, and related dev tooling (eslint, stylelint, prettier, typescript-eslint, etc.) within existing semver ranges.
  • Replaced  decompress  (CVE-2026-53486, zip-slip arbitrary file write — package is abandoned with no upstream fix) with  adm-zip  in  update-translations.mts  (the only usage, a dev-only Lokalise translation-sync script). Reimplemented the previous  strip: 1  behavior manually and added an explicit path-traversal guard for defense in depth.
  • Fixed 8 files that failed lint under the newer  typescript-eslint  ( no-unnecessary-type-assertion  became stricter) via  eslint --fix  — a direct side effect of the dependency bump, no behavior changes.

Files touched

  • package.json ,  pnpm-lock.yaml 
  • update-translations.mts 
  • 8 component files with unnecessary type assertions removed

@kflemin
kflemin merged commit a1e3a45 into main Sep 22, 2026
2 checks passed
@kflemin
kflemin deleted the vulnerability-updates branch September 22, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant