Skip to content

build: update cross-repo angular dependencies (21.2.x)#32966

Open
angular-robot wants to merge 1 commit intoangular:21.2.xfrom
angular-robot:ng-renovate/21.2.x-cross-repo-angular-dependencies
Open

build: update cross-repo angular dependencies (21.2.x)#32966
angular-robot wants to merge 1 commit intoangular:21.2.xfrom
angular-robot:ng-renovate/21.2.x-cross-repo-angular-dependencies

Conversation

@angular-robot
Copy link
Copy Markdown
Contributor

@angular-robot angular-robot commented Apr 8, 2026

This PR contains the following updates:

Package Change Age Adoption Passing Confidence Type Update
@angular/animations (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/cdk 21.2.521.2.6 age adoption passing confidence devDependencies patch
@angular/common (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/compiler (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/compiler-cli (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/core (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/forms (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/localize 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/material 21.2.521.2.6 age adoption passing confidence devDependencies patch
@angular/ng-dev 1c95e8451c559e devDependencies digest
@angular/platform-browser (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/platform-server (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/router (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
@angular/service-worker (source) 21.2.721.2.8 age adoption passing confidence devDependencies patch
devinfra ba726e730bd830 git_override digest
rules_angular 6c36180346e8fe git_override digest

🔡 If you wish to disable git hash updates, add ":disableDigestUpdates" to the extends array in your config.


  • If you want to rebase/retry this PR, check this box

Release Notes

angular/angular (@​angular/animations)

v21.2.8

Compare Source

compiler
Commit Type Description
e40d378f3e fix handle nested brackets in host object bindings
compiler-cli
Commit Type Description
2c6781071f fix error for type parameter declarations
core
Commit Type Description
82192deda9 fix handle missing serialized container hydration data
057cc6d09d fix remove obsolete iOS cursor pointer hack in event delegation
language-service
Commit Type Description
7797671257 fix get quick info at local var location to align with TS semantics and support type narrowing
angular/components (@​angular/cdk)

v21.2.6

Compare Source

material
Commit Type Description
5b4bbe9c4f fix select: wrong transform origin when opening upwards inside another overlay (#​33032)

@angular-robot angular-robot added action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only] labels Apr 8, 2026
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates various Angular dependencies from version 21.2.7 to 21.2.8 across the project and updates the pnpm lockfile accordingly. Additionally, a deprecation note was added to the basic-ftp package in the lockfile. I have identified a high-severity issue: the basic-ftp package should be upgraded to version 5.2.1 to address the security vulnerability, rather than simply documenting the deprecation.

basic-ftp@5.2.0:
resolution: {integrity: sha512-VoMINM2rqJwJgfdHq6RiUudKt2BV+FY5ZFezP/ypmwayk68+NzzAQy4XXLlqsGD4MCzq3DrmNFD/uUmBJuGoXw==}
engines: {node: '>=10.0.0'}
deprecated: Security vulnerability fixed in 5.2.1, please upgrade
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The deprecation message for basic-ftp@5.2.0 is helpful, but it is better to upgrade the dependency to 5.2.1 to resolve the security vulnerability rather than just noting it in the lockfile.

@angular-robot angular-robot force-pushed the ng-renovate/21.2.x-cross-repo-angular-dependencies branch from 4aa7144 to b573c64 Compare April 8, 2026 22:16
@angular-robot angular-robot changed the title build: update cross-repo angular dependencies to v21.2.8 (21.2.x) build: update cross-repo angular dependencies (21.2.x) Apr 8, 2026
See associated pull request for more information.
@angular-robot angular-robot force-pushed the ng-renovate/21.2.x-cross-repo-angular-dependencies branch from b573c64 to 06d2631 Compare April 9, 2026 09:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: build & ci Related the build and CI infrastructure of the project target: automation This PR is targeted to only merge into the branch defined in Github [bot use only]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant