We are facing vulnerability issue with angular 12.24 when scanned with black duck tool.
Below are the packages with issues.
- PostCss - 7.0.36. Recommended -8.3.6
- url-parse - 1.5.1 Recommended -1.5.3
- glob-parent - 3.1.0 Recommended -6.0.1
- einaros/ws - 6.2.2 Recommended -8.0.0
How can I update these versions as these are dependent packages of core packages installed.
Tried solutions
npm audit fix - Not working
Updated to latest angular version - Not working.
Updated package-lock.json - Getting overwritten on npm i.
Thanks in advance.