npm audit run on my project and got me this
High Command Injection
Dependency of @angular-devkit/build-angular [dev]
You can fix this without waiting for a new version of the package @angular-devkit/build-angular.
Just do the following steps:
package.json file by adding resolutions section with proper version of package tree-kill:"resolutions": {
"tree-kill": "1.2.2"
}
package-lock.json by running command:npx npm-force-resolutions
rm -r node_modules
npm install
Run npm audit to check that your project does not have anymore this problem. And don't forget to commit modified files package.json and package-lock.json.
More information about NPM Force Resolutions.