Skip to content

Conversation

@Eric-Wasson
Copy link
Contributor

Fixed deprecated feature policy header and added some new permissions to deny that aren't needed.

Same change as the PR #1743 from the server repo.

@github-actions
Copy link

# npm audit report

@angular/common  20.0.0-next.0 - 20.3.13
Severity: high
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client - https://github.com/advisories/GHSA-58c5-g7wp-6w37
fix available via `npm audit fix`
node_modules/@angular/common
  @angular/forms  4.4.0-RC.0 - 4.4.0 || 20.0.0-next.0 - 20.3.13
  Depends on vulnerable versions of @angular/common
  Depends on vulnerable versions of @angular/platform-browser
  node_modules/@angular/forms
  @angular/platform-browser  20.0.0-next.0 - 20.3.13
  Depends on vulnerable versions of @angular/common
  node_modules/@angular/platform-browser
  @angular/platform-browser-dynamic  20.0.0-next.0 - 20.3.13
  Depends on vulnerable versions of @angular/common
  Depends on vulnerable versions of @angular/platform-browser
  node_modules/@angular/platform-browser-dynamic
  @angular/router  10.0.0-next.0 - 10.0.0-rc.1 || 20.0.0-next.0 - 20.3.13
  Depends on vulnerable versions of @angular/common
  Depends on vulnerable versions of @angular/platform-browser
  node_modules/@angular/router

body-parser  2.2.0
Severity: moderate
body-parser is vulnerable to denial of service when url encoding is used - https://github.com/advisories/GHSA-wqch-xfxh-vrr4
fix available via `npm audit fix`
node_modules/express/node_modules/body-parser

6 vulnerabilities (1 moderate, 5 high)

To address all issues, run:
  npm audit fix

@Eric-Wasson Eric-Wasson added the bug Something isn't working label Nov 27, 2025
@Eric-Wasson Eric-Wasson moved this to 🚧 In progress in 🍂 Sprint November '25 Nov 27, 2025
@Eric-Wasson Eric-Wasson moved this from 🚧 In progress to ⏳🙄 Waiting for in 🍂 Sprint November '25 Nov 27, 2025
@gluafamichl gluafamichl merged commit 7da2a14 into master Dec 1, 2025
3 of 4 checks passed
@gluafamichl gluafamichl deleted the 1658-feature-policy-deprecated branch December 1, 2025 15:36
@github-project-automation github-project-automation bot moved this from ⏳🙄 Waiting for to 🎉 Done in 🍂 Sprint November '25 Dec 1, 2025
@Eric-Wasson Eric-Wasson restored the 1658-feature-policy-deprecated branch December 5, 2025 11:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

Status: 🎉 Done

Development

Successfully merging this pull request may close these issues.

3 participants