diff --git a/README.md b/README.md index 70475bc..68ffdc1 100644 --- a/README.md +++ b/README.md @@ -49,7 +49,9 @@ A lightweight library for dynamically validate Angular reactive forms using [cla "@angular/common": ">= 2.0.0 <= ^18.0.0", "@angular/core": ">= 2.0.0 <= ^18.0.0", "@angular/forms": ">= 2.0.0 <= ^18.0.0", - "class-validator": "^0.12.2" + "class-validator": ">= 0.12.0 <= ^0.14.0" + +###### _While this library will function with any version of class-validator within this range, we strongly recommend using class-validator ^0.14.0 or later due to a critical [security vulnerability](https://github.com/typestack/class-validator/blob/develop/CHANGELOG.md#:~:text=forbidUnknownValues%20option%20is%20enabled%20by%20default) addressed in versions 0.14.0 and beyond. This ensures the highest level of security for your application._ ## Usage ### Defining classes with validators and deserializers diff --git a/libs/ngx-reactive-form-class-validator/package.json b/libs/ngx-reactive-form-class-validator/package.json index 5f5cfbd..039b71a 100644 --- a/libs/ngx-reactive-form-class-validator/package.json +++ b/libs/ngx-reactive-form-class-validator/package.json @@ -2,7 +2,7 @@ "name": "ngx-reactive-form-class-validator", "description": "A lightweight library for dynamically validate Angular reactive forms using class-validator library.", "license": "MIT", - "version": "1.8.1", + "version": "1.8.2", "keywords": [ "ng", "angular", @@ -27,6 +27,6 @@ "@angular/common": ">= 2.0.0 <= ^18.0.0", "@angular/core": ">= 2.0.0 <= ^18.0.0", "@angular/forms": ">= 2.0.0 <= ^18.0.0", - "class-validator": "^0.12.2" + "class-validator": ">= 0.12.0 <= ^0.14.0" } } diff --git a/package.json b/package.json index 9220bfa..d3df4b1 100644 --- a/package.json +++ b/package.json @@ -57,7 +57,7 @@ "bump-version:patch": "cd libs/ngx-reactive-form-class-validator && npm version patch --force", "pre-publish:minor": "run-s bump-version:minor build:lib-pack", "pre-publish:major": "run-s bump-version:major build:lib-pack", - "pre-publish:patch": "run-s bump-version:patch build:lib-pack commit-git" + "pre-publish:patch": "run-s bump-version:patch build:lib-pack" }, "private": true, "dependencies": {