Bump the zeppelin-web-angular-security-updates group across 1 directory with 11 updates - #5438
Open
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/zeppelin-web-angular/zeppelin-web-angular-security-updates-ee2b507370
branch
from
September 4, 2026 14:55
23db788 to
fa414d8
Compare
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/zeppelin-web-angular/zeppelin-web-angular-security-updates-ee2b507370
branch
from
September 13, 2026 06:46
fa414d8 to
cb925d2
Compare
…ry with 11 updates Bumps the zeppelin-web-angular-security-updates group with 7 updates in the /zeppelin-web-angular directory: | Package | From | To | | --- | --- | --- | | [@angular/common](https://github.com/angular/angular/tree/HEAD/packages/common) | `21.2.15` | `21.2.20` | | [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) | `21.2.15` | `21.2.19` | | [@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core) | `21.2.15` | `21.2.20` | | [rollup](https://github.com/rollup/rollup) | `0.25.8` | `4.60.4` | | [hono](https://github.com/honojs/hono) | `4.12.23` | `4.13.7` | | [shell-quote](https://github.com/ljharb/shell-quote) | `1.8.3` | `1.9.0` | | [tar](https://github.com/isaacs/node-tar) | `7.5.15` | `7.5.22` | Updates `@angular/common` from 21.2.15 to 21.2.20 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v21.2.20/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v21.2.20/packages/common) Updates `@angular/compiler` from 21.2.15 to 21.2.19 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v21.2.19/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v21.2.19/packages/compiler) Updates `@angular/core` from 21.2.15 to 21.2.20 - [Release notes](https://github.com/angular/angular/releases) - [Changelog](https://github.com/angular/angular/blob/v21.2.20/CHANGELOG.md) - [Commits](https://github.com/angular/angular/commits/v21.2.20/packages/core) Updates `rollup` from 0.25.8 to 4.60.4 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG-0.md) - [Commits](rollup/rollup@v0.25.8...v4.60.4) Updates `hono` from 4.12.23 to 4.13.7 - [Release notes](https://github.com/honojs/hono/releases) - [Commits](honojs/hono@v4.12.23...v4.13.7) Updates `http-proxy-middleware` from 2.0.9 to 2.0.10 - [Release notes](https://github.com/chimurai/http-proxy-middleware/releases) - [Changelog](https://github.com/chimurai/http-proxy-middleware/blob/v2.0.10/CHANGELOG.md) - [Commits](chimurai/http-proxy-middleware@v2.0.9...v2.0.10) Updates `launch-editor` from 2.14.0 to 2.14.1 - [Commits](vitejs/launch-editor@v2.14.0...v2.14.1) Updates `shell-quote` from 1.8.3 to 1.9.0 - [Changelog](https://github.com/ljharb/shell-quote/blob/main/CHANGELOG.md) - [Commits](ljharb/shell-quote@v1.8.3...v1.9.0) Updates `piscina` from 5.1.4 to 5.2.0 - [Release notes](https://github.com/piscinajs/piscina/releases) - [Changelog](https://github.com/piscinajs/piscina/blob/v5.2.0/CHANGELOG.md) - [Commits](piscinajs/piscina@v5.1.4...v5.2.0) Updates `tar` from 7.5.15 to 7.5.22 - [Release notes](https://github.com/isaacs/node-tar/releases) - [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md) - [Commits](isaacs/node-tar@v7.5.15...v7.5.22) Updates `webpack-dev-server` from 5.2.3 to 5.2.6 - [Release notes](https://github.com/webpack/webpack-dev-server/releases) - [Changelog](https://github.com/webpack/webpack-dev-server/blob/v5.2.6/CHANGELOG.md) - [Commits](webpack/webpack-dev-server@v5.2.3...v5.2.6) --- updated-dependencies: - dependency-name: "@angular/common" dependency-version: 21.2.19 dependency-type: direct:production dependency-group: zeppelin-web-angular-security-updates - dependency-name: "@angular/compiler" dependency-version: 21.2.19 dependency-type: direct:production dependency-group: zeppelin-web-angular-security-updates - dependency-name: "@angular/core" dependency-version: 21.2.17 dependency-type: direct:production dependency-group: zeppelin-web-angular-security-updates - dependency-name: hono dependency-version: 4.13.4 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: http-proxy-middleware dependency-version: 2.0.10 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: launch-editor dependency-version: 2.14.1 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: piscina dependency-version: 5.2.0 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: rollup dependency-version: 4.60.4 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: shell-quote dependency-version: 1.9.0 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: tar dependency-version: 7.5.22 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates - dependency-name: webpack-dev-server dependency-version: 5.2.5 dependency-type: indirect dependency-group: zeppelin-web-angular-security-updates ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/npm_and_yarn/zeppelin-web-angular/zeppelin-web-angular-security-updates-ee2b507370
branch
from
September 13, 2026 08:22
cb925d2 to
ddd4187
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the zeppelin-web-angular-security-updates group with 7 updates in the /zeppelin-web-angular directory:
21.2.1521.2.2021.2.1521.2.1921.2.1521.2.200.25.84.60.44.12.234.13.71.8.31.9.07.5.157.5.22Updates
@angular/commonfrom 21.2.15 to 21.2.20Release notes
Sourced from @angular/common's releases.
... (truncated)
Changelog
Sourced from @angular/common's changelog.
... (truncated)
Commits
caf6166fix(http): run root interceptors in the terminal request chainfec5977fix(http): match header values exactly when deletinge33d69afix(http): preserve immutability of materialized clones948a8d6fix(http): distinguish repeated transfer cache params9949dccfix(http): enable xsrf for root-provided HttpClient91df739fix(http): prevent caching of responses with Set-Cookie headers86a56dcfix(common): Limits date format string lengthbcb1b7efix(http): preserve empty referrer option in HttpRequesta810a31fix(http): Rejects non-HTTP(S) URLs in JSONP requestsbc55749fix(common): use cryptographically secure SHA-256 for transfer cache key gene...Updates
@angular/compilerfrom 21.2.15 to 21.2.19Release notes
Sourced from @angular/compiler's releases.
... (truncated)
Changelog
Sourced from @angular/compiler's changelog.
... (truncated)
Commits
7b884f5fix(compiler): restrict possible event handler check to property names longer...e2660c3fix(compiler): disallow i18n event attributesdc9c996fix(compiler): sanitize two-way propertiesae1c8a1fix(compiler): move projection attributes into constantsUpdates
@angular/corefrom 21.2.15 to 21.2.20Release notes
Sourced from @angular/core's releases.
... (truncated)
Changelog
Sourced from @angular/core's changelog.
... (truncated)
Commits
6afe6fafix(core): sanitize host bindings on concrete hosts7b884f5fix(compiler): restrict possible event handler check to property names longer...e2660c3fix(compiler): disallow i18n event attributes5a693bafix(core): reject dynamic script host elements6bcce11fix(core): avoid caching missing locale data88832c8fix(core): validate lowercase SVG animation attribute names (#69269)3551074fix(platform-server): harden platform location origin validation during SSRbc55749fix(common): use cryptographically secure SHA-256 for transfer cache key gene...d846326fix(common): skip transfer cache for uncacheable HTTP traffice245d40fix(http): skip transfer cache for fetch credentialed requestsUpdates
rollupfrom 0.25.8 to 4.60.4Release notes
Sourced from rollup's releases.
... (truncated)
Changelog
Sourced from rollup's changelog.
... (truncated)
Commits
d311a844.60.46aa3248fix: stabilize chunk assignment across parallel file reads (#6362)82a0fe7Resolve vulnerabilities (#6375)71f5ebcchore(deps): update dependency lru-cache to v11 (#6371)af91d77chore(deps): lock file maintenance (#6373)65e7b94chore(deps): update react monorepo to v19 (major) (#6372)642587ffix(deps): update minor/patch updates (#6370)b47bdab4.60.315c5f33Add again some unneeded dev dependencies, to make some builds succeed12195dcfix: do not rename nested "exports" bindings that do not conflict (#6360)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for rollup since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
honofrom 4.12.23 to 4.13.7Release notes
Sourced from hono's releases.
... (truncated)
Commits
eebdf7b4.13.72b8ed40Merge commit from forkcac0c4d4.13.6dac5d57refactor(on-handler): use forEach for consistent handler iteration (#5326)ec648d6chore: bumpeditorconfig-checker(#5336)e2740d5fix(types): allow symbol keys in Context<any> get and set fallbacks (#5300)499c35efix(client): normalize root WebSocket URLs (#5291)50b8788fix(client): keep a param value of "index" in $url() and $path() (#5297)06880c44.13.5531e9c5Merge commit from forkMaintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for hono since your current version.
Updates
http-proxy-middlewarefrom 2.0.9 to 2.0.10Release notes
Sourced from http-proxy-middleware's releases.
Changelog
Sourced from http-proxy-middleware's changelog.
Commits
f0be839chore(package.json): v2.0.10 (#1271)19c860dci(github-actions): update publish.yml (#1270)d0f7d63fix: harden proxy-table matching to prevent routing bypass (#1268)Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for http-proxy-middleware since your current version.
Updates
launch-editorfrom 2.14.0 to 2.14.1Commits
3f97c64v2.14.10cc9550fix: reject UNC paths (#138)afd1ab9ci: run tests on mac and windows (#136)0bfa328test: add some tests for launch-editor package (#135)1b006aechore: add README (#134)Updates
shell-quotefrom 1.8.3 to 1.9.0Changelog
Sourced from shell-quote's changelog.
Commits
db09fc7v1.9.07ff5488[Fix]parse: finalize tokens in linear time (GHSA-395f-4hp3-45gv)b4bafa2[actions] Windows + node 5/7: install deps with a modern node3fb739d[actions] Windows + node 4/6/7: pin eslint to 9 before install, since npm 2/3...abe0163[actions] retrynpm installon Windows to survive npm 2/3 staging-rename flake7a76c1a[Fix]quote: escape leading~to prevent shell tilde-expansion75e8497[actions] update workflowsdca6e21[New] add types9aa9e8f[Dev Deps] updateeslint9ba368a[Dev Deps] apparentlyjackspeakDescription has been truncated