Security issue with angular build dependent packages angular

Viewed 75

We are facing vulnerability issue with angular 12.24 when scanned with black duck tool.

Below are the packages with issues.

  1. PostCss - 7.0.36. Recommended -8.3.6
  2. url-parse - 1.5.1 Recommended -1.5.3
  3. glob-parent - 3.1.0 Recommended -6.0.1
  4. einaros/ws - 6.2.2 Recommended -8.0.0

How can I update these versions as these are dependent packages of core packages installed.

Tried solutions

npm audit fix - Not working

Updated to latest angular version - Not working.

Updated package-lock.json - Getting overwritten on npm i.

Thanks in advance.

0 Answers
Related