From 74d1e5af3df0410158537b3a9dab2830fa40d399 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Thu, 2 Apr 2026 06:59:26 +0000 Subject: [PATCH 1/2] chore(deps): update angular monorepo to v21.2.7 --- yarn.lock | 102 +++++++++++++++++++++++++++--------------------------- 1 file changed, 51 insertions(+), 51 deletions(-) diff --git a/yarn.lock b/yarn.lock index 7a402c6b0..224f22f50 100644 --- a/yarn.lock +++ b/yarn.lock @@ -514,13 +514,13 @@ __metadata: linkType: hard "@angular/animations@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/animations@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/animations@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/core": 21.2.6 - checksum: 10/e166cd4292aa3e1ac031b1f05780c7b42f9d960b921f2d7aa3824a57d57205565ee5af7229f89d8ad81e5111274d853c64e383c4cbd47e6d76dac3be6fbebf7a + "@angular/core": 21.2.7 + checksum: 10/a7a151665f5ab37788d688dcd685ad3bf82a7d3cda69e2c3288003beb194562f45d419a5dc3cc21d777faa546330e1dbbc2ef7e369aae122c92e53bf4dd2b398 languageName: node linkType: hard @@ -634,20 +634,20 @@ __metadata: linkType: hard "@angular/common@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/common@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/common@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/core": 21.2.6 + "@angular/core": 21.2.7 rxjs: ^6.5.3 || ^7.4.0 - checksum: 10/95afcb8ab108bbaffc2874a756d488ebe9e878349b5a866cbfd2e2d485dabdb6357fac4ffdc24e8f292a9b0bc3fd9d8db856e11d8f23e00ff1a27b7345896326 + checksum: 10/56de81da4d7aa93085c68ecd63642a4524f3d7de8e870ae8f0362a2f889a8bb550f64c7f3a6f7e084cf550a2d9b3b370cdf3b69900efc6a3514271ad133a6b69 languageName: node linkType: hard "@angular/compiler-cli@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/compiler-cli@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/compiler-cli@npm:21.2.7" dependencies: "@babel/core": "npm:7.29.0" "@jridgewell/sourcemap-codec": "npm:^1.4.14" @@ -658,7 +658,7 @@ __metadata: tslib: "npm:^2.3.0" yargs: "npm:^18.0.0" peerDependencies: - "@angular/compiler": 21.2.6 + "@angular/compiler": 21.2.7 typescript: ">=5.9 <6.1" peerDependenciesMeta: typescript: @@ -666,26 +666,26 @@ __metadata: bin: ng-xi18n: bundles/src/bin/ng_xi18n.js ngc: bundles/src/bin/ngc.js - checksum: 10/c832adc4daaf4b634c50241da92392f60d6ffc0af539134b4fac994913024c6a9cbb080452f3d01621afdba88949fbcf1b8905eec6fd9b6eacac5d0f8ced6945 + checksum: 10/df79ef22b82429f8df5332a0f61c49e6f872066216b9b52c38d3f0a180b0d785d35d8fe7634c9b54439b0e3628a5b5af43a251bdc813cbe8001287808558f483 languageName: node linkType: hard "@angular/compiler@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/compiler@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/compiler@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" - checksum: 10/14fbd5307bf55c55faf692025da3a35cd34b42b76c4c29402115fd2331e22210bd2b6588c62dfbd7085a1039a1a4c1e9456f51d70e8804156d08575bbc71c129 + checksum: 10/83ff061e60b65cf57e753112d749a148fa8d03b9aa3a9b457146e6c4101db426f6263261a1ddce6ec484dcb14ad8144ab9435407e9f767ec11f274a79bd5457f languageName: node linkType: hard "@angular/core@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/core@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/core@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/compiler": 21.2.6 + "@angular/compiler": 21.2.7 rxjs: ^6.5.3 || ^7.4.0 zone.js: ~0.15.0 || ~0.16.0 peerDependenciesMeta: @@ -693,82 +693,82 @@ __metadata: optional: true zone.js: optional: true - checksum: 10/cfa6512c36926319fcafb4ad16a12e9814c24404eb61dca5f505f3a63bdba8824da5b31aed384299979ed7eec1c7d72a0968c6c88c76e30d48ba6fc94fc4eda3 + checksum: 10/de482c2430136a5dcd2ff4066c7b6d1c4fda9225c89d2c4385c20f75c8adcb2e2cb3825ca2028c3ad8f886f76b1ef620a80dc82700a4980c464e24463e0827ab languageName: node linkType: hard "@angular/forms@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/forms@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/forms@npm:21.2.7" dependencies: "@standard-schema/spec": "npm:^1.0.0" tslib: "npm:^2.3.0" peerDependencies: - "@angular/common": 21.2.6 - "@angular/core": 21.2.6 - "@angular/platform-browser": 21.2.6 + "@angular/common": 21.2.7 + "@angular/core": 21.2.7 + "@angular/platform-browser": 21.2.7 rxjs: ^6.5.3 || ^7.4.0 - checksum: 10/a0c045ea738cc02990282b7f0db0f3841cb2b705e5520d2ca99306c342faea6d08197a7c7980d073f95dc674e21d6f6fcd93aaae3b78cdce4359c49a1602fbab + checksum: 10/6bbd6208254068a361ace006f9d1d8ed63e0358c47e9ec512f892c23007d9409e15a92acc16bbbe7aac050b4e9d82a4e2f8468c067e0b57d3927a0f6a04c7686 languageName: node linkType: hard "@angular/platform-browser-dynamic@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/platform-browser-dynamic@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/platform-browser-dynamic@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/common": 21.2.6 - "@angular/compiler": 21.2.6 - "@angular/core": 21.2.6 - "@angular/platform-browser": 21.2.6 - checksum: 10/de913a2b1635d9a11b42c37f8de8371b61065e473032821f60f0a38788fc88858c3813837cec510a6b3b944840a4ae1479579a92b32c0e3d483a25a9f286d230 + "@angular/common": 21.2.7 + "@angular/compiler": 21.2.7 + "@angular/core": 21.2.7 + "@angular/platform-browser": 21.2.7 + checksum: 10/86a8c660375ed81fae64114d0a6ea38330ef196d354e91058aa2a19954c3b8abda8e92bdc18704b164ef4f69d27bd2d2de161e2e7579a91b7d51f53675d90de9 languageName: node linkType: hard "@angular/platform-browser@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/platform-browser@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/platform-browser@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/animations": 21.2.6 - "@angular/common": 21.2.6 - "@angular/core": 21.2.6 + "@angular/animations": 21.2.7 + "@angular/common": 21.2.7 + "@angular/core": 21.2.7 peerDependenciesMeta: "@angular/animations": optional: true - checksum: 10/67821c8b2925a68f9392cfb96795058b78bdf7a3dc791195e412ef7a7bcf355cf93badbf4ab95f2d465abf17d6ce4141259722fc85469fb773b9427574a42ed0 + checksum: 10/db8e838664d449ab50b23e022313f922f4d03505d3fc19ce2e488a2e69cceba4889b178d14864a21b19af4f74b5ec45f96e3e384651e7ee8571d170d8a7babeb languageName: node linkType: hard "@angular/platform-server@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/platform-server@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/platform-server@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" xhr2: "npm:^0.2.0" peerDependencies: - "@angular/common": 21.2.6 - "@angular/compiler": 21.2.6 - "@angular/core": 21.2.6 - "@angular/platform-browser": 21.2.6 + "@angular/common": 21.2.7 + "@angular/compiler": 21.2.7 + "@angular/core": 21.2.7 + "@angular/platform-browser": 21.2.7 rxjs: ^6.5.3 || ^7.4.0 - checksum: 10/12fe067ef170b9d8379304e9e8c314e2cfd59bb72257f6f7e09d92914e92691eea8d2473c614666ef434bad835d9987d8a365eac8158e7209907121021a1eaca + checksum: 10/534495babe151f3e2331f27f0f6197f6a50c43748158436dc71ec4ed7a10a6509618fc872c82c14c108b6176a7d071b2247789b4f56f76a80f529dd6f278ec9c languageName: node linkType: hard "@angular/router@npm:^21.1.3": - version: 21.2.6 - resolution: "@angular/router@npm:21.2.6" + version: 21.2.7 + resolution: "@angular/router@npm:21.2.7" dependencies: tslib: "npm:^2.3.0" peerDependencies: - "@angular/common": 21.2.6 - "@angular/core": 21.2.6 - "@angular/platform-browser": 21.2.6 + "@angular/common": 21.2.7 + "@angular/core": 21.2.7 + "@angular/platform-browser": 21.2.7 rxjs: ^6.5.3 || ^7.4.0 - checksum: 10/6eb46a3c4204979c1d291e3bee608bd8fe2ac8bd94fe321fd894eace8f0b90ceace210c0ab65d935eaad128bced95909210c0055a8c3b7d11d6d93bbd802fb40 + checksum: 10/be9bae48af406b5c1703f0be2486e8767483c10966cdb4b19c721e83e9b02ca1b44651b89ea0a22288a73b92120c1ab9ea03e4c000f52b90abad50c5ada54eba languageName: node linkType: hard From 2083a1a54e4441a22153b66a1173d25e05fd6917 Mon Sep 17 00:00:00 2001 From: Frankie Moran Date: Thu, 2 Apr 2026 09:12:50 +0100 Subject: [PATCH 2/2] (update): known issues --- yarn-audit-known-issues | 2 ++ 1 file changed, 2 insertions(+) diff --git a/yarn-audit-known-issues b/yarn-audit-known-issues index 485768801..95d7e23b3 100644 --- a/yarn-audit-known-issues +++ b/yarn-audit-known-issues @@ -2,6 +2,8 @@ {"value":"@angular/ssr","children":{"ID":1113513,"Issue":"Angular SSR has an Open Redirect via X-Forwarded-Prefix","URL":"https://github.com/advisories/GHSA-xh43-g2fq-wjrj","Severity":"moderate","Vulnerable Versions":">=21.0.0-next.0 <21.1.5","Tree Versions":["21.1.4"],"Dependents":["opal-frontend@workspace:."]}} {"value":"@angular/ssr","children":{"ID":1115534,"Issue":"Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR","URL":"https://github.com/advisories/GHSA-vfx2-hv2g-xj5f","Severity":"moderate","Vulnerable Versions":">=21.0.0-next.0 <21.2.3","Tree Versions":["21.1.4"],"Dependents":["opal-frontend@workspace:."]}} {"value":"ajv","children":{"ID":1113715,"Issue":"ajv has ReDoS when using `$data` option","URL":"https://github.com/advisories/GHSA-2g4f-4pwh-qvx6","Severity":"moderate","Vulnerable Versions":">=7.0.0-alpha.0 <8.18.0","Tree Versions":["8.17.1"],"Dependents":["schema-utils@npm:4.3.3"]}} +{"value":"lodash","children":{"ID":1115806,"Issue":"lodash vulnerable to Code Injection via `_.template` imports key names","URL":"https://github.com/advisories/GHSA-r5fr-rjxr-66jc","Severity":"high","Vulnerable Versions":">=4.0.0 <=4.17.23","Tree Versions":["4.17.23"],"Dependents":["@cypress/webpack-preprocessor@virtual:a675e69e845cebadc36cee9a38065a1960f4aab74a9924442784ad5431c94d53a7f1d4962754c45f81da4004ef26e80c7c562b8c146cee281975b943df474817#npm:7.0.2"]}} +{"value":"lodash","children":{"ID":1115810,"Issue":"lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit`","URL":"https://github.com/advisories/GHSA-f23m-r3pf-42rh","Severity":"moderate","Vulnerable Versions":"<=4.17.23","Tree Versions":["4.17.23"],"Dependents":["@cypress/webpack-preprocessor@virtual:a675e69e845cebadc36cee9a38065a1960f4aab74a9924442784ad5431c94d53a7f1d4962754c45f81da4004ef26e80c7c562b8c146cee281975b943df474817#npm:7.0.2"]}} {"value":"minimatch","children":{"ID":1113459,"Issue":"minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern","URL":"https://github.com/advisories/GHSA-3ppc-4f35-3m26","Severity":"high","Vulnerable Versions":"<3.1.3","Tree Versions":["3.1.2"],"Dependents":["find-cypress-specs@npm:1.47.2"]}} {"value":"minimatch","children":{"ID":1113465,"Issue":"minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern","URL":"https://github.com/advisories/GHSA-3ppc-4f35-3m26","Severity":"high","Vulnerable Versions":">=9.0.0 <9.0.6","Tree Versions":["9.0.5"],"Dependents":["mocha@npm:11.7.5"]}} {"value":"minimatch","children":{"ID":1113538,"Issue":"minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments","URL":"https://github.com/advisories/GHSA-7r86-cg39-jmmj","Severity":"high","Vulnerable Versions":"<3.1.3","Tree Versions":["3.1.2"],"Dependents":["find-cypress-specs@npm:1.47.2"]}}