Bump @angular/platform-server from 21.2.8 to 21.2.9#5302
Bump @angular/platform-server from 21.2.8 to 21.2.9#5302dependabot[bot] wants to merge 1 commit into
Conversation
Patches GHSA-45q2-gjvg-7973 (high) — protocol-relative and backslash URLs in Angular Platform-Server allow SSRF. root 21.2.8 → 21.2.9 (PR #5302) packages/core 20.3.18 → 20.3.19 (PR #5301) Bumps applied via package.json + bun install (bun.lock is the source of truth; legacy package-lock.json files left untouched).
Bumps [@angular/platform-server](https://github.com/angular/angular/tree/HEAD/packages/platform-server) from 21.2.8 to 21.2.9. - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v21.2.9/packages/platform-server) --- updated-dependencies: - dependency-name: "@angular/platform-server" dependency-version: 21.2.9 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
adeec54 to
9451eab
Compare
|
Superseded by lockfile / override applied directly on develop. Closing as no longer needed; dependabot will reopen if a new advisory bumps the floor. |
1 similar comment
|
Superseded by lockfile / override applied directly on develop. Closing as no longer needed; dependabot will reopen if a new advisory bumps the floor. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps @angular/platform-server from 21.2.8 to 21.2.9.
Release notes
Sourced from @angular/platform-server's releases.
Changelog
Sourced from @angular/platform-server's changelog.
... (truncated)
Commits
e0b5078fix(platform-server): prevent SSRF bypasses via protocol-relative and backsla...f603d47fix(core): escape forward slashes in transfer state to prevent crawler indexing