Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-13956

Upgrade @angular-devkit/build-angular 18.2.11 or later

Attach filesAttach ScreenshotVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 2.0.0-M4, 2.0.0
    • None
    • Core UI
    • None

    Description

      Can you please upgrade angularjs to latest minor point release as well as http_proxy_middleware? Scanners are picking up that there are vulnerabilities.

       

      ```

       xnox@chainguard:/tmp/nifi/nifi-frontend/src/main/frontend$ npm audit
       # npm audit report
       
       http-proxy-middleware  3.0.0 - 3.0.2
       Severity: high
       Denial of service in http-proxy-middleware - https://github.com/advisories/GHSA-c7qv-q95q-8v27
       fix available via `npm audit fix --force`
       Will install @angular-devkit/build-angular@18.2.10, which is outside the stated dependency range
       node_modules/http-proxy-middleware
         @angular-devkit/build-angular  18.0.0-next.0 - 18.2.9 || 19.0.0-next.0 - 19.0.0-next.9
         Depends on vulnerable versions of http-proxy-middleware
         node_modules/@angular-devkit/build-angular
       
       2 high severity vulnerabilities
       
       To address all issues, run:
         npm audit fix --force

      ```

       

      Note usually dependabot can help with these, and it is a good practice to run `npm audit` prior to cutting a release.

      Attachments

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            mcgilman Matt Gilman
            xnox Dimitri John Ledkov
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 40m
                40m

                Slack

                  Issue deployment