Known vulnerability in a dependency
The package manager's audit reports a security advisory for an installed package.
What it means
Diopter runs npm audit --json (or the pnpm, yarn and bun equivalents) and normalizes the result: severity, the vulnerable package and its installed version, the dependency chain that pulls it in, and the version range that fixes it. Transitive dependencies of the Angular CLI itself show up here too; they matter less at runtime but still fail most security policies.
How to fix it
Update the vulnerable package to the patched range, or the direct dependency that brings it in (the finding names both). npm audit fix / pnpm audit --fix apply the non-breaking updates; the UI runs it from the Security tab.
What it looks like
As printed by diopter check; the UI and the Markdown report show the same finding with its location.
[DIOP0501] High vulnerability in `undici`@7.24.4: undici vulnerable to TLS certificate validation bypass (GHSA-vmh5-mc38-953g), via @angular/build > undici.
fix: Update `undici` to >=7.28.0 (updating `@angular/build` to 21.2.24 brings it in), or run `npm audit fix`.diopter check --audit-level <critical|high|moderate|low>.diopter next to your dev server, or the static report from diopter build.get-vulnerabilities (diopter mcp).