-
Notifications
You must be signed in to change notification settings - Fork 11.9k
Labels
area: @angular/builddevkit/build-angular:dev-serverfreq1: lowOnly reported by a handful of users who observe it rarelyOnly reported by a handful of users who observe it rarelyseverity6: securitytype: bug/fix
Description
Command
build
Description
The current vite
requirement for Angular 20.2 is 7.1.2
our build system identified this vulnerability CVE https://nvd.nist.gov/vuln/detail/CVE-2025-58751 that is corrected in 7.1.5
.
Is there any reason that ~7.1.5
can't be specified so that this and future minor patches can be used?
Describe the solution you'd like
No response
Describe alternatives you've considered
No response
MohamedSamyHossebo
Metadata
Metadata
Assignees
Labels
area: @angular/builddevkit/build-angular:dev-serverfreq1: lowOnly reported by a handful of users who observe it rarelyOnly reported by a handful of users who observe it rarelyseverity6: securitytype: bug/fix