Skip to content

@angular-devkit/build-angular 17 uses vulnerable undici 6.11.1 #30066

@SymbioticKilla

Description

@SymbioticKilla

Command

version

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

Hi,
is it possible to update it to 6.21.1?
https://nvd.nist.gov/vuln/detail/CVE-2025-22150

Thanks!

Minimal Reproduction

package.json

Exception or Error


Your Environment

17.3.15

Anything else relevant?

No response

Activity

added a commit that references this issue on Apr 9, 2025
606b99c
added 2 commits that reference this issue on Apr 9, 2025
df87df9
b99c2c0
self-assigned this
on Apr 9, 2025
added theissue type on Apr 9, 2025
added a commit that references this issue on Apr 9, 2025
5aa53b4
alan-agius4

alan-agius4 commented on Apr 9, 2025

@alan-agius4
Collaborator

Closed via #30071

angular-automatic-lock-bot

angular-automatic-lock-bot commented on May 10, 2025

@angular-automatic-lock-bot

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

locked and limited conversation to collaborators on May 10, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

Projects

No projects

Milestone

No milestone

Relationships

None yet

    Development

    No branches or pull requests

      Participants

      @alan-agius4@SymbioticKilla

      Issue actions

        @angular-devkit/build-angular 17 uses vulnerable undici 6.11.1 · Issue #30066 · angular/angular-cli