Skip to content

1019326: Resolved dependabot issues by updating angular dependency#97

Merged
CCMKarthik1611 merged 1 commit intomasterfrom
EJ2-1019326-dep
Apr 8, 2026
Merged

1019326: Resolved dependabot issues by updating angular dependency#97
CCMKarthik1611 merged 1 commit intomasterfrom
EJ2-1019326-dep

Conversation

@BalajiLoganathanSF4826
Copy link
Copy Markdown
Collaborator

Bug description

Dependabot flagged an outdated and vulnerable version of angular in package.json.
The existing version (15.0.0) contained security advisories and compatibility warnings. Updating was required to maintain dependency stability and remove security alerts.

Root cause

The project was using an older angular (15.0.0) version that Dependabot identified as vulnerable or outdated. This caused dependency mismatch risks, potential security exposure, and triggered automated alerts. The version was not aligned with the recommended patch level for the framework used.

Solution description

Updated angular to the latest compatible patch version 19.2.18 as recommended by Dependabot.
This resolves the security alert, ensures dependency consistency, and improves build/runtime stability for the React PDF Viewer examples.

The following issues will be resolved by this change:

high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
high - Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

Copy link
Copy Markdown
Collaborator

@CCMKarthik1611 CCMKarthik1611 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes are fine.

Copy link
Copy Markdown
Collaborator

@CCMKarthik1611 CCMKarthik1611 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes are fine.

@CCMKarthik1611 CCMKarthik1611 merged commit 493e1f9 into master Apr 8, 2026
1 check passed
@CCMKarthik1611 CCMKarthik1611 deleted the EJ2-1019326-dep branch April 8, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants