Skip to content

Bump @angular/platform-server from 21.2.8 to 21.2.9#5302

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/angular/platform-server-21.2.9
Closed

Bump @angular/platform-server from 21.2.8 to 21.2.9#5302
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/angular/platform-server-21.2.9

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 16, 2026

Bumps @angular/platform-server from 21.2.8 to 21.2.9.

Release notes

Sourced from @​angular/platform-server's releases.

21.2.9

core

Commit Description
fix - f603d4714f escape forward slashes in transfer state to prevent crawler indexing

http

Commit Description
fix - 540536c386 add CSP nonce support to JsonpClientBackend
fix - 63a857b874 Don't on Passthru outside of reactive context

platform-server

Commit Description
fix - e0b5078cf2 prevent SSRF bypasses via protocol-relative and backslash URLs

router

Commit Description
fix - 684e9fd53d normalize multiple leading slashes in URL parser
Changelog

Sourced from @​angular/platform-server's changelog.

21.2.9 (2026-04-15)

core

Commit Type Description
f603d4714f fix escape forward slashes in transfer state to prevent crawler indexing

http

Commit Type Description
540536c386 fix add CSP nonce support to JsonpClientBackend
63a857b874 fix Don't on Passthru outside of reactive context

platform-server

Commit Type Description
e0b5078cf2 fix prevent SSRF bypasses via protocol-relative and backslash URLs

router

Commit Type Description
684e9fd53d fix normalize multiple leading slashes in URL parser

22.0.0-next.7 (2026-04-08)

Breaking Changes

core

  • The second argument of appRef.bootstrap does not accept any anymore. Make sure the element you pass is not nullable.
    • TypeScript versions older than 6.0 are no longer supported.
  • ComponentFactoryResolver and ComponentFactory are no longer available. Pass the component class directly to APIs that previously required a factory, such as ViewContainerRef.createComponent or use the standalone createComponentFunction.
  • ComponentFactoryResolver and ComponentFactory are no longer available. Pass the component class directly to APIs that previously required a factory, such as ViewContainerRef.createComponent or use the standalone createComponent function.

platform-browser

  • This removes styles when they appear to no longer be used by an associated host. However other DOM on the page may still be affected by those styles if not leveraging ViewEncapsulation.Emulated or if those styles are used by elements outside of Angular, potentially causing other DOM to appear unstyled.

router

  • The currentSnapshot parameter in CanMatchFn and the canMatch method of the CanMatch interface is now required. While this was already the behavior of the Router at runtime, existing class implementations of CanMatch must now include the third argument to satisfy the interface.

compiler

Commit Type Description
2ce0e98f79 fix handle nested brackets in host object bindings

compiler-cli

Commit Type Description
7f9450219f feat Adds warning for prefetch without main defer trigger
ab061a7610 fix error for type parameter declarations
9218140348 fix resolve TCB mapping failure for safe property reads with as any

core

Commit Type Description
a0aa8304cd feat bootstrap via ApplicationRef with config
9c55fcb3e6 feat de-duplicate host directives
8fe025f514 feat drop support for TypeScript 5.9
77f1ca08e4 fix handle missing serialized container hydration data

... (truncated)

Commits
  • e0b5078 fix(platform-server): prevent SSRF bypasses via protocol-relative and backsla...
  • f603d47 fix(core): escape forward slashes in transfer state to prevent crawler indexing
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Apr 16, 2026
norman-abramovitz pushed a commit that referenced this pull request May 10, 2026
Patches GHSA-45q2-gjvg-7973 (high) — protocol-relative and backslash
URLs in Angular Platform-Server allow SSRF.

  root           21.2.8 → 21.2.9   (PR #5302)
  packages/core  20.3.18 → 20.3.19 (PR #5301)

Bumps applied via package.json + bun install (bun.lock is the source
of truth; legacy package-lock.json files left untouched).
Bumps [@angular/platform-server](https://github.com/angular/angular/tree/HEAD/packages/platform-server) from 21.2.8 to 21.2.9.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v21.2.9/packages/platform-server)

---
updated-dependencies:
- dependency-name: "@angular/platform-server"
  dependency-version: 21.2.9
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/angular/platform-server-21.2.9 branch from adeec54 to 9451eab Compare May 10, 2026 19:05
@nabramovitz
Copy link
Copy Markdown
Contributor

Superseded by lockfile / override applied directly on develop. Closing as no longer needed; dependabot will reopen if a new advisory bumps the floor.

1 similar comment
@norman-abramovitz
Copy link
Copy Markdown
Contributor

Superseded by lockfile / override applied directly on develop. Closing as no longer needed; dependabot will reopen if a new advisory bumps the floor.

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 10, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/npm_and_yarn/angular/platform-server-21.2.9 branch May 10, 2026 19:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants