Skip to content

Bump @angular/ssr from 17.0.5 to 19.2.21 in /scripts/webframeworks-deploy-tests/angular#9978

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/scripts/webframeworks-deploy-tests/angular/angular/ssr-19.2.21
Open

Bump @angular/ssr from 17.0.5 to 19.2.21 in /scripts/webframeworks-deploy-tests/angular#9978
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/scripts/webframeworks-deploy-tests/angular/angular/ssr-19.2.21

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 25, 2026

Bumps @angular/ssr from 17.0.5 to 19.2.21.

Release notes

Sourced from @​angular/ssr's releases.

19.2.21

@​angular/ssr

Commit Description
fix - 288e22816 prevent open redirect via X-Forwarded-Prefix header
fix - 2a72d7483 validate host headers to prevent header-based SSRF

19.2.20

@​angular-devkit/build-angular

Commit Description
fix - 0e5421ba7 update webpack to 5.105.0

19.2.19

@​angular/build

Commit Description
fix - 4d8ea27a1 update vite to v6.4.1

19.2.18

@​angular/ssr

Commit Description
fix - 9136a5d13 prevent malicious URL from overriding host

19.2.17

@​angular/build

Commit Description
fix - 365d525b5 update vite to 6.3.6

19.2.16

@​angular-devkit/build-angular

Commit Description
fix - b0f4330a9 avoid extra tick in SSR builds

@​angular/build

Commit Description
fix - ee5c5f823 avoid extra tick in SSR dev-server builds

@​angular/ssr

Commit Description
feat - 32980f7e7 introduce BootstrapContext for isolated server-side rendering

Breaking Changes

@​angular/ssr

  • The server-side bootstrapping process has been changed to eliminate the reliance on a global platform injector.

    Before:

... (truncated)

Changelog

Sourced from @​angular/ssr's changelog.

19.2.21 (2026-02-23)

@​angular/ssr

Commit Type Description
288e22816 fix prevent open redirect via X-Forwarded-Prefix header
2a72d7483 fix validate host headers to prevent header-based SSRF

19.2.20 (2026-02-13)

@​angular-devkit/build-angular

Commit Type Description
0e5421ba7 fix update webpack to 5.105.0

21.1.4 (2026-02-11)

@​angular/build

Commit Type Description
7a9dd6b47 fix correctly resolve absolute setup file paths in Vitest

20.3.16 (2026-02-09)

@​angular/cli

Commit Type Description
656888a25 fix update dependency @​modelcontextprotocol/sdk to v1.26.0

21.1.3 (2026-02-05)

... (truncated)

Commits
  • 4d9442a release: cut the v19.2.21 release
  • 288e228 fix(@​angular/ssr): prevent open redirect via X-Forwarded-Prefix header
  • 2a72d74 fix(@​angular/ssr): validate host headers to prevent header-based SSRF
  • 747393c release: cut the v19.2.20 release
  • d37b749 build: update pnpm to 10.15.0
  • 0e5421b fix(@​angular-devkit/build-angular): update webpack to 5.105.0
  • 399c3ec release: cut the v19.2.19 release
  • 4d8ea27 fix(@​angular/build): update vite to v6.4.1
  • 8590f19 release: cut the v19.2.18 release
  • 9136a5d fix(@​angular/ssr): prevent malicious URL from overriding host
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [@angular/ssr](https://github.com/angular/angular-cli) from 17.0.5 to 19.2.21.
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@17.0.5...v19.2.21)

---
updated-dependencies:
- dependency-name: "@angular/ssr"
  dependency-version: 19.2.21
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants