Skip to content

chore(deps): update angular-cli monorepo to v17 (major) #426

chore(deps): update angular-cli monorepo to v17 (major)

chore(deps): update angular-cli monorepo to v17 (major) #426

Triggered via pull request November 8, 2023 16:05
Status Failure
Total duration 3m 33s
Artifacts

image.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

10 errors, 12 warnings, and 2 notices
Scan
CVE-2023-38545 - CRITICAL severity - heap based buffer overflow in the SOCKS5 proxy handshake vulnerability in curl
Scan
CVE-2023-38039 - HIGH severity - out of heap memory issue due to missing limit on header quantity vulnerability in curl
Scan
CVE-2023-38545 - CRITICAL severity - heap based buffer overflow in the SOCKS5 proxy handshake vulnerability in libcurl
Scan
CVE-2023-38039 - HIGH severity - out of heap memory issue due to missing limit on header quantity vulnerability in libcurl
Scan
CVE-2023-4863 - HIGH severity - Heap buffer overflow in WebP Codec vulnerability in libwebp
Scan
CVE-2023-3138 - HIGH severity - InitExt.c can overwrite unintended portions of the Display structure if the extension request leads to a buffer overflow vulnerability in libx11
Scan
CVE-2023-43787 - HIGH severity - integer overflow in XCreateImage() leading to a heap overflow vulnerability in libx11
Scan
CVE-2023-35945 - HIGH severity - HTTP/2 memory leak in nghttp2 codec vulnerability in nghttp2-libs
Scan
CVE-2023-44487 - HIGH severity - Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) vulnerability in nghttp2-libs
Build
buildx failed with: ERROR: failed to solve: process "/bin/sh -c yarn run lint && yarn run build && yarn run build:ssr && yarn run prerender" did not complete successfully: exit code: 3
Scan
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Scan
CVE-2023-2975 - MEDIUM severity - AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries vulnerability in libcrypto3
Scan
CVE-2023-3446 - MEDIUM severity - Excessive time spent checking DH keys and parameters vulnerability in libcrypto3
Scan
CVE-2023-3817 - MEDIUM severity - Excessive time spent checking DH q parameter value vulnerability in libcrypto3
Scan
CVE-2023-5363 - MEDIUM severity - Incorrect cipher key and IV length processing vulnerability in libcrypto3
Scan
CVE-2023-2975 - MEDIUM severity - AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries vulnerability in libssl3
Scan
CVE-2023-3446 - MEDIUM severity - Excessive time spent checking DH keys and parameters vulnerability in libssl3
Scan
CVE-2023-3817 - MEDIUM severity - Excessive time spent checking DH q parameter value vulnerability in libssl3
Scan
CVE-2023-5363 - MEDIUM severity - Incorrect cipher key and IV length processing vulnerability in libssl3
Scan
CVE-2023-43785 - MEDIUM severity - out-of-bounds memory access in _XkbReadKeySyms() vulnerability in libx11
Scan
CVE-2023-43786 - MEDIUM severity - stack exhaustion from infinite recursion in PutSubImage() vulnerability in libx11
Build
The `set-output` command is deprecated and will be disabled soon. Please upgrade to using Environment Files. For more information see: https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/
Scan
CVE-2023-38546 - LOW severity - cookie injection with none file vulnerability in curl
Scan
CVE-2023-38546 - LOW severity - cookie injection with none file vulnerability in libcurl