angular.courses
DIOP0501SecurityCI gate

Known vulnerability in a dependency

The package manager's audit reports a security advisory for an installed package.

What it means

Diopter runs npm audit --json (or the pnpm, yarn and bun equivalents) and normalizes the result: severity, the vulnerable package and its installed version, the dependency chain that pulls it in, and the version range that fixes it. Transitive dependencies of the Angular CLI itself show up here too; they matter less at runtime but still fail most security policies.

How to fix it

Update the vulnerable package to the patched range, or the direct dependency that brings it in (the finding names both). npm audit fix / pnpm audit --fix apply the non-breaking updates; the UI runs it from the Security tab.

What it looks like

As printed by diopter check; the UI and the Markdown report show the same finding with its location.

[DIOP0501] High vulnerability in `undici`@7.24.4: undici vulnerable to TLS certificate validation bypass (GHSA-vmh5-mc38-953g), via @angular/build > undici.
  fix: Update `undici` to >=7.28.0 (updating `@angular/build` to 21.2.24 brings it in), or run `npm audit fix`.
In CI
diopter check --audit-level <critical|high|moderate|low>.
In the UI
The Security tab, from diopter next to your dev server, or the static report from diopter build.
For agents
MCP tool get-vulnerabilities (diopter mcp).

Learn more