Update Angular to resolve vulnerability CVE-2021-4231
Open
- Dominant language
- TypeScript
- Stars
- 2.5k
- Forks
- 232
- PR merge metrics
- No merged PRs in 30d
Description
Versions of Angular < 11.0.5 have a cross-site scripting vulnerability as described at https://github.com/advisories/GHSA-c75v-2vq8-878f.
Contributor guide
Research direction
Start by locating the Angular dependency in the repository's dependency manifests and checking its current version against 11.0.5. Update it to a non-vulnerable version, then run the repository's existing checks; done means the dependency is no longer below 11.0.5 and the checks pass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- angular, typescript
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 32/100