Skip to content

Chore(deps): bump @angular/common from 21.2.13 to 21.2.17 in /with-angular#34

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/with-angular/angular/common-21.2.17
Closed

Chore(deps): bump @angular/common from 21.2.13 to 21.2.17 in /with-angular#34
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/with-angular/angular/common-21.2.17

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown

Bumps @angular/common from 21.2.13 to 21.2.17.

Release notes

Sourced from @​angular/common's releases.

21.2.17

common

Commit Description
fix - 86a56dc279 Limits date format string length
fix - d846326b07 skip transfer cache for uncacheable HTTP traffic
fix - bc55749698 use cryptographically secure SHA-256 for transfer cache key generation

compiler

Commit Description
fix - dc9c99636d sanitize two-way properties

core

Commit Description
fix - 1523061137 harden TransferState restoration against DOM clobbering
fix - 88832c84f8 validate lowercase SVG animation attribute names (#69269)

http

Commit Description
fix - bcb1b7ea25 preserve empty referrer option in HttpRequest
fix - a810a319d1 Rejects non-HTTP(S) URLs in JSONP requests
fix - e245d40c4d skip transfer cache for fetch credentialed requests

platform-server

Commit Description
fix - 35510746b7 harden platform location origin validation during SSR
refactor - 13fb0afe93 deprecate ServerXhr (#69255)

service-worker

Commit Description
fix - b9d29381bb Strips sensitive headers on cross-origin redirects

Deprecations

platform-server

  • XHR support in @angular/platform-server is deprecated. Use standard fetch APIs instead.

21.2.16

common

Commit Description
fix - f6d8e642b0 only strip a literal /index.html suffix from URLs

compiler

Commit Description
fix - ae1c8a1f7a move projection attributes into constants

core

Commit Description
fix - 3fd6897a67 harden inherit definition feature against polluted prototypes
fix - 7e38336dc7 use Object.create(null) for LOCALE_DATA as a hardening measure

platform-server

... (truncated)

Changelog

Sourced from @​angular/common's changelog.

21.2.17 (2026-06-10)

Deprecations

platform-server

  • XHR support in @angular/platform-server is deprecated. Use standard fetch APIs instead.

common

Commit Type Description
86a56dc279 fix Limits date format string length
d846326b07 fix skip transfer cache for uncacheable HTTP traffic
bc55749698 fix use cryptographically secure SHA-256 for transfer cache key generation

compiler

Commit Type Description
dc9c99636d fix sanitize two-way properties

core

Commit Type Description
1523061137 fix harden TransferState restoration against DOM clobbering
88832c84f8 fix validate lowercase SVG animation attribute names (#69269)

http

Commit Type Description
bcb1b7ea25 fix preserve empty referrer option in HttpRequest
a810a319d1 fix Rejects non-HTTP(S) URLs in JSONP requests
e245d40c4d fix skip transfer cache for fetch credentialed requests

platform-server

Commit Type Description
35510746b7 fix harden platform location origin validation during SSR
13fb0afe93 refactor deprecate ServerXhr (#69255)

service-worker

Commit Type Description
b9d29381bb fix Strips sensitive headers on cross-origin redirects

20.3.25 (2026-06-10)

Deprecations

platform-server

  • XHR support in @angular/platform-server is deprecated. Use standard fetch APIs instead.

common

Commit Type Description
9f443bc24c fix Limits date format string length
566ad05f20 fix skip transfer cache for uncacheable HTTP traffic
1a62130a6b fix use cryptographically secure SHA-256 for transfer cache key generation

compiler

| Commit | Type | Description |

... (truncated)

Commits
  • 86a56dc fix(common): Limits date format string length
  • bcb1b7e fix(http): preserve empty referrer option in HttpRequest
  • a810a31 fix(http): Rejects non-HTTP(S) URLs in JSONP requests
  • bc55749 fix(common): use cryptographically secure SHA-256 for transfer cache key gene...
  • d846326 fix(common): skip transfer cache for uncacheable HTTP traffic
  • e245d40 fix(http): skip transfer cache for fetch credentialed requests
  • f6d8e64 fix(common): only strip a literal /index.html suffix from URLs
  • 582a417 fix(http): exclude withCredentials requests from transfer cache
  • 5c6d6df fix(http): skip TransferCache for cookie-bearing requests by default
  • 300f61f fix(common): sanitize placeholder
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

View with Codesmith Autofix with Codesmith
Need help on this PR? Tag /codesmith with what you need. Autofix is disabled.

Bumps [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common) from 21.2.13 to 21.2.17.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.17/packages/common)

---
updated-dependencies:
- dependency-name: "@angular/common"
  dependency-version: 21.2.17
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jun 16, 2026
@socket-security

Copy link
Copy Markdown

Dependency limit exceeded — report not shown.

This pull request scan exceeded the 10,000-dependency limit applied to this scan, so the results are incomplete and may be inaccurate. To avoid reporting false positives, Socket has not posted a report.

Upgrade your plan to raise the dependency limit and get complete reports, or view the partial scan in the dashboard.

Socket is always free for open source. If this is a non-commercial open source project, contact us to request a free Team account.

@yosriady yosriady closed this Jun 16, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/with-angular/angular/common-21.2.17 branch June 16, 2026 02:49
yosriady pushed a commit that referenced this pull request Jun 16, 2026
…ith-angular

Completes the Dependabot @angular/common 21.2.13->21.2.17 bump (PR #34),
which failed CI because it bumped @angular/common alone: @angular/core and
the other framework packages stayed on 21.2.13, leaving the high-severity
advisories unresolved and creating a peer-dependency mismatch
(@angular/common@21.2.17 requires @angular/core@21.2.17).

- Bump all @angular/* framework packages (common, compiler, core, forms,
  platform-browser, router, compiler-cli) to ^21.2.17 in lockstep. This
  clears the high advisories GHSA-rgjc-h3x7-9mwg, GHSA-39pv-4j6c-2g6v,
  GHSA-48r7-hpm6-gfxm, GHSA-p3vc-36g9-x9gr and GHSA-q6f4-qqrg-jv6x, all of
  which are only patched in >=21.2.17.
- Exempt the @angular framework packages from the 7-day minimumReleaseAge
  gate: 21.2.17 is the sole patched release and is still inside the window,
  so the gate would otherwise block the fix.
- Force ws>=8.21.0 via overrides to clear GHSA-96hv-2xvq-fx4p (memory
  exhaustion DoS) pulled in transitively through viem, the remaining high
  that kept the with-angular audit red.

@angular/build and @angular/cli stay at 21.2.11 (no 21.2.17 exists; their
^21.0.0 peer ranges accept the bumped framework). Verified: pnpm audit
--prod --audit-level=high reports no vulnerabilities, frozen-lockfile
install is consistent, and ng build succeeds.
yosriady pushed a commit that referenced this pull request Jun 16, 2026
… 23.4.6 to 24.1.2 in with-crossmint (#35)

* fix(security): update i18next from 23.4.6 to 24.1.2

* fix(security): update shell-quote from 1.8.3 to 1.8.4

Forces the patched shell-quote (>=1.8.4) for the GHSA-w7jw-789q-3m8p
critical advisory, pulled in transitively via @crossmint/client-sdk-react-ui.
Resolves the failing critical-gated pnpm audit for with-crossmint.

* fix(security): update @angular/* to 21.2.17 and force ws>=8.21.0 in with-angular

Completes the Dependabot @angular/common 21.2.13->21.2.17 bump (PR #34),
which failed CI because it bumped @angular/common alone: @angular/core and
the other framework packages stayed on 21.2.13, leaving the high-severity
advisories unresolved and creating a peer-dependency mismatch
(@angular/common@21.2.17 requires @angular/core@21.2.17).

- Bump all @angular/* framework packages (common, compiler, core, forms,
  platform-browser, router, compiler-cli) to ^21.2.17 in lockstep. This
  clears the high advisories GHSA-rgjc-h3x7-9mwg, GHSA-39pv-4j6c-2g6v,
  GHSA-48r7-hpm6-gfxm, GHSA-p3vc-36g9-x9gr and GHSA-q6f4-qqrg-jv6x, all of
  which are only patched in >=21.2.17.
- Exempt the @angular framework packages from the 7-day minimumReleaseAge
  gate: 21.2.17 is the sole patched release and is still inside the window,
  so the gate would otherwise block the fix.
- Force ws>=8.21.0 via overrides to clear GHSA-96hv-2xvq-fx4p (memory
  exhaustion DoS) pulled in transitively through viem, the remaining high
  that kept the with-angular audit red.

@angular/build and @angular/cli stay at 21.2.11 (no 21.2.17 exists; their
^21.0.0 peer ranges accept the bumped framework). Verified: pnpm audit
--prod --audit-level=high reports no vulnerabilities, frozen-lockfile
install is consistent, and ng build succeeds.

---------

Co-authored-by: aikido-autofix[bot] <119856028+aikido-autofix[bot]@users.noreply.github.com>
Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant