Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 3, 2025

Bumps @angular/core from 20.3.14 to 21.0.2.

Release notes

Sourced from @​angular/core's releases.

21.0.2

compiler

Commit Description
fix - 78fd159b78 prevent XSS via SVG animation attributeName and MathML/SVG URLs

21.0.1

compiler-cli

Commit Description
fix - 39c577bc36 do not type check native controls with ControlValueAccessor
fix - 8d3a89a477 escape angular control flow in jsdoc
fix - bc34083d34 ignore non-existent files

core

Commit Description
fix - 0ea1e07174 apply bootstrap-options migration to platformBrowserDynamic
fix - 70507b8c1c debug data causing memory leak for root effects
fix - a55482fca3 notify profiler events in case of errors
fix - 49ad7c6508 use injected DOCUMENT for CSP_NONCE
perf - cc1ec09931 avoid repeat searches for field directive

forms

Commit Description
feat - 7d5c7cf99a add DI option for classes on Field directive
fix - 8acf5d2756 allow dynamic type bindings on signal form controls
fix - de5fca94c5 run reset as untracked

http

Commit Description
fix - 3240d856d9 prevent XSRF token leakage to protocol-relative URLs

migrations

Commit Description
fix - f394215b14 detect structural ngTemplateOutlet and ngComponentOutlet

VSCode Extension: 21.0.0

  • fix(language-service): address potential memory leak during project creation (89095946cf)
  • fix(language-server): fix directory renaming on Windows (3f7111a9c3)

21.0.0

common

Commit Description
feat - c795960ada Add experimental support for the Navigation API (#63406)
feat - 9eac43cf46 Support of optional keys for the KeyValue pipe (#48814)
feat - a1868c9d13 update to cldr 47 (#64032)
fix - 196fa500a3 properly type ngComponentOutlet (#64561)

... (truncated)

Changelog

Sourced from @​angular/core's changelog.

21.0.2 (2025-12-01)

compiler

Commit Type Description
78fd159b78 fix prevent XSS via SVG animation attributeName and MathML/SVG URLs

20.3.15 (2025-12-01)

compiler

Commit Type Description
d1ca8ae043 fix prevent XSS via SVG animation attributeName and MathML/SVG URLs

19.2.17 (2025-12-01)

compiler

Commit Type Description
7c42e2ebeb fix prevent XSS via SVG animation attributeName and MathML/SVG URLs

19.2.16 (2025-11-26)

http

Commit Type Description
05fe6686a9 fix prevent XSRF token leakage to protocol-relative URLs

21.1.0-next.0 (2025-11-25)

... (truncated)

Commits
  • 78fd159 fix(compiler): prevent XSS via SVG animation attributeName and MathML/SVG URLs
  • a408415 refactor(migrations): don't migration the server bootstrapApplicaiton on zo...
  • 151616d refactor(core): show error message on signal error
  • 0ae14cb test(core): test bundling of dynamic component creation and bindings
  • 908b5a4 refactor: replace getDocument() with inject(DOCUMENT)
  • 6b20adf refactor: add mark for signal forms
  • 49ad7c6 fix(core): use injected DOCUMENT for CSP_NONCE
  • 7d5c7cf feat(forms): add DI option for classes on Field directive
  • 477df38 docs: improve core package API documentation with additional reference links
  • 0e458c7 refactor(core): Remove toggles used for zoneless by default migration
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core) from 20.3.14 to 21.0.2.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/21.0.2/packages/core)

---
updated-dependencies:
- dependency-name: "@angular/core"
  dependency-version: 21.0.2
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Dec 3, 2025
@cloudflare-workers-and-pages
Copy link

cloudflare-workers-and-pages bot commented Dec 3, 2025

Deploying orpc with  Cloudflare Pages  Cloudflare Pages

Latest commit: 23278e5
Status: ✅  Deploy successful!
Preview URL: https://398da3a9.orpc-1qh.pages.dev
Branch Preview URL: https://dependabot-npm-and-yarn-angu-ml85.orpc-1qh.pages.dev

View logs

@dosubot dosubot bot added the size:XS This PR changes 0-9 lines, ignoring generated files. label Dec 3, 2025
@coderabbitai
Copy link

coderabbitai bot commented Dec 3, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@codecov
Copy link

codecov bot commented Dec 3, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@pkg-pr-new
Copy link

pkg-pr-new bot commented Dec 3, 2025

More templates

@orpc/ai-sdk

npm i https://pkg.pr.new/@orpc/ai-sdk@1273

@orpc/arktype

npm i https://pkg.pr.new/@orpc/arktype@1273

@orpc/client

npm i https://pkg.pr.new/@orpc/client@1273

@orpc/contract

npm i https://pkg.pr.new/@orpc/contract@1273

@orpc/experimental-durable-iterator

npm i https://pkg.pr.new/@orpc/experimental-durable-iterator@1273

@orpc/hey-api

npm i https://pkg.pr.new/@orpc/hey-api@1273

@orpc/interop

npm i https://pkg.pr.new/@orpc/interop@1273

@orpc/json-schema

npm i https://pkg.pr.new/@orpc/json-schema@1273

@orpc/nest

npm i https://pkg.pr.new/@orpc/nest@1273

@orpc/openapi

npm i https://pkg.pr.new/@orpc/openapi@1273

@orpc/openapi-client

npm i https://pkg.pr.new/@orpc/openapi-client@1273

@orpc/otel

npm i https://pkg.pr.new/@orpc/otel@1273

@orpc/experimental-pino

npm i https://pkg.pr.new/@orpc/experimental-pino@1273

@orpc/experimental-publisher

npm i https://pkg.pr.new/@orpc/experimental-publisher@1273

@orpc/experimental-publisher-durable-object

npm i https://pkg.pr.new/@orpc/experimental-publisher-durable-object@1273

@orpc/experimental-ratelimit

npm i https://pkg.pr.new/@orpc/experimental-ratelimit@1273

@orpc/react

npm i https://pkg.pr.new/@orpc/react@1273

@orpc/react-query

npm i https://pkg.pr.new/@orpc/react-query@1273

@orpc/experimental-react-swr

npm i https://pkg.pr.new/@orpc/experimental-react-swr@1273

@orpc/server

npm i https://pkg.pr.new/@orpc/server@1273

@orpc/shared

npm i https://pkg.pr.new/@orpc/shared@1273

@orpc/solid-query

npm i https://pkg.pr.new/@orpc/solid-query@1273

@orpc/standard-server

npm i https://pkg.pr.new/@orpc/standard-server@1273

@orpc/standard-server-aws-lambda

npm i https://pkg.pr.new/@orpc/standard-server-aws-lambda@1273

@orpc/standard-server-fastify

npm i https://pkg.pr.new/@orpc/standard-server-fastify@1273

@orpc/standard-server-fetch

npm i https://pkg.pr.new/@orpc/standard-server-fetch@1273

@orpc/standard-server-node

npm i https://pkg.pr.new/@orpc/standard-server-node@1273

@orpc/standard-server-peer

npm i https://pkg.pr.new/@orpc/standard-server-peer@1273

@orpc/svelte-query

npm i https://pkg.pr.new/@orpc/svelte-query@1273

@orpc/tanstack-query

npm i https://pkg.pr.new/@orpc/tanstack-query@1273

@orpc/trpc

npm i https://pkg.pr.new/@orpc/trpc@1273

@orpc/valibot

npm i https://pkg.pr.new/@orpc/valibot@1273

@orpc/vue-colada

npm i https://pkg.pr.new/@orpc/vue-colada@1273

@orpc/vue-query

npm i https://pkg.pr.new/@orpc/vue-query@1273

@orpc/zod

npm i https://pkg.pr.new/@orpc/zod@1273

commit: 23278e5

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 4, 2025

Superseded by #1277.

@dependabot dependabot bot closed this Dec 4, 2025
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/angular/core-21.0.2 branch December 4, 2025 09:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code size:XS This PR changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant