rfellows opened a new pull request, #11745:
URL: https://github.com/apache/nifi/pull/11745

   # NIFI-16411: Clear nifi-frontend npm audit findings with Angular 21.2 
patches
   
   ## Description
   
   `npm audit` on `nifi-frontend` reported 39 findings (0 critical, 20 high, 19 
moderate, 0 low). This change brings that count to 0 by applying Angular 21.2 
patch releases, aligning the CLI and build tooling to the same line, and taking 
the remaining lockfile patches from `npm audit fix` (without `--force`).
   
   Nx stays on 22.7.8. Angular 22 is not part of this change. No UI behavior 
changes are intended.
   
   JIRA: https://issues.apache.org/jira/browse/NIFI-16411
   
   ## What's Changed
   
   ### nifi-frontend
   
   - Bump the Angular runtime from 21.2.19 to 21.2.24 (`@angular/animations`, 
`common`, `compiler`, `core`, `forms`, `platform-browser`, 
`platform-browser-dynamic`, `router`).
   - Bump `@angular/cdk` and `@angular/material` from 21.1.6 to 21.2.14.
   - Align `@angular/cli`, `@angular/build`, `@angular/compiler-cli`, 
`@angular-devkit/build-angular`, `@angular-devkit/core`, 
`@angular-devkit/schematics`, and `@schematics/angular` to 21.2.24. Bump 
`ng-packagr` from 21.1.0 to 21.2.7.
   - Bump `rxjs` from `~7.8.1` to `~7.8.2` and `@vitest/coverage-v8` from 
`^4.1.1` to `^4.1.11`. `vitest` was already `^4.1.11`.
   - Apply `npm audit fix` lockfile patches, including `express`, 
`body-parser`, `qs`, `nanoid`, `ip-address`, `fast-uri`, `brace-expansion`, and 
module-federation. The lockfile resolves `ip-address` 10.7.2 and `undici` 
8.11.2. The `undici` override remains `^8.10.0`.
   - Remove stale overrides that no longer surface advisories when unpinned: 
`@hono/node-server` `^2.0.5` and `@modelcontextprotocol/sdk` `^1.30.0`.
   - Add overrides: `smol-toml` `^1.8.0` (resolves 1.9.0) for 
GHSA-7w5x-hrqm-74c2; `axios` `^1.20.0` (resolves 1.20.0) for the axios 
1.0.0–1.19.0 advisory cluster (GHSA-vh66-26gq-q6x8 and related); `js-yaml` 
`^4.3.2` (resolves 4.3.2) for GHSA-2883-xcg3-v3hh.
   - Close Angular advisories GHSA-ff3f-86qr-9cv3 (router SSR denial of 
service), GHSA-hh8m-fm6v-7cvg (sanitizer bypass), GHSA-p297-fm68-3q8c 
(HttpTransferCache), and GHSA-w4pp-8pjf-rmxw (pacote via the CLI).
   - Install used `npm install --legacy-peer-deps` for the CLI and build hop 
from 21.1.5 to 21.2.24.
   - Verification: `npx nx run-many -t lint,test` and then `build` exited 0 
across `nifi`, `nifi-registry`, `nifi-jolt-transform-ui`, `update-attribute`, 
`standard-content-viewer`, and `shared`.
   
   This commit satisfies these open Dependabot pull requests:
   
   - https://github.com/apache/nifi/pull/11740 — Bump `@angular/router` from 
21.2.19 to 21.2.24. Sibling Angular packages are aligned to 21.2.24, and 
Material and CDK to 21.2.14.
   - https://github.com/apache/nifi/pull/11736 — Bump `undici` from 8.10.0 to 
8.11.2. The lockfile resolves 8.11.2; the override remains `^8.10.0`.
   - https://github.com/apache/nifi/pull/11732 — Bump `ip-address` from 10.4.0 
to 10.7.2 via `npm audit fix`. The lockfile resolves 10.7.2.
   
   ## Key Features
   
   - **Stay on Angular 21.2**: Findings are cleared with 21.2.24 and 
Material/CDK 21.2.14. Angular 22 is not taken. Nx remains 22.7.8.
   - **Peer-dependency install**: The 21.1.5 to 21.2.24 CLI and build hop was 
installed with `npm install --legacy-peer-deps`.
   - **Override hygiene**: Two overrides that no longer hid advisories were 
removed. Three new overrides pin `smol-toml`, `axios`, and `js-yaml` to 
versions outside the reported ranges.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to