Skip to content

Bump @angular/compiler from 20.3.14 to 20.3.18#2776

Merged
amontenegro merged 1 commit intomainfrom
dependabot/npm_and_yarn/angular/compiler-20.3.18
Apr 6, 2026
Merged

Bump @angular/compiler from 20.3.14 to 20.3.18#2776
amontenegro merged 1 commit intomainfrom
dependabot/npm_and_yarn/angular/compiler-20.3.18

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 14, 2026

Bumps @angular/compiler from 20.3.14 to 20.3.18.

Release notes

Sourced from @​angular/compiler's releases.

20.3.18

compiler

Commit Description
fix - 02fbf08890 disallow translations of iframe src

core

Commit Description
fix - 72126f9a08 sanitize translated attribute bindings with interpolations
fix - 626bc8bc20 sanitize translated form attributes

20.3.17

core

Commit Description
fix - 7f9de3c118 block creation of sensitive URI attributes from ICU messages

Breaking Changes

core

  • Angular now only applies known attributes from HTML in translated ICU content. Unknown attributes are dropped and not rendered.

    (cherry picked from commit 03da204b6daa5e4583e0d0968c2107390bbd8235)

20.3.16

core

Commit Description
fix - c2c2b4aaa8 sanitize sensitive attributes on SVG script elements

20.3.15

compiler

Commit Description
fix - d1ca8ae043 prevent XSS via SVG animation attributeName and MathML/SVG URLs
Changelog

Sourced from @​angular/compiler's changelog.

20.3.18 (2026-03-12)

compiler

Commit Type Description
02fbf08890 fix disallow translations of iframe src

core

Commit Type Description
72126f9a08 fix sanitize translated attribute bindings with interpolations
626bc8bc20 fix sanitize translated form attributes

22.0.0-next.3 (2026-03-12)

compiler

Commit Type Description
78dea55351 fix disallow translations of iframe src

core

Commit Type Description
999c14eaab fix reverts "feat(core): add support for nested animations"
de0eb4c656 fix sanitize translated form attributes

21.2.4 (2026-03-12)

compiler

Commit Type Description
ed2d324f9c fix disallow translations of iframe src

core

Commit Type Description
abbd8797bb fix reverts "feat(core): add support for nested animations"
d1dcd16c5b fix sanitize translated form attributes

22.0.0-next.2 (2026-03-11)

Breaking Changes

core

  • createNgModuleRef was removed, use createNgModule instead

core

Commit Type Description
b918beda32 feat allow debouncing signals

... (truncated)

Commits
  • 02fbf08 fix(compiler): disallow translations of iframe src
  • c2c2b4a fix(core): sanitize sensitive attributes on SVG script elements
  • d1ca8ae fix(compiler): prevent XSS via SVG animation attributeName and MathML/SVG URLs
  • See full diff in compare view

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 14, 2026
@github-actions
Copy link
Copy Markdown
Contributor

github-actions bot commented Mar 14, 2026

🚀 Preview Deployment

Your UI docs preview is ready!

Preview URL: https://orcid.github.io/orcid-angular/runway/dependabot-npm_and_yarn-angular-compiler-20.3.18/

This preview will be updated automatically when you push new commits to this PR.


Deployed from commit: 7c88da9

@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/angular/compiler-20.3.18 branch 2 times, most recently from 0a83855 to ec7fbdb Compare March 20, 2026 00:35
Bumps [@angular/compiler](https://github.com/angular/angular/tree/HEAD/packages/compiler) from 20.3.16 to 20.3.18.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v20.3.18/packages/compiler)

---
updated-dependencies:
- dependency-name: "@angular/compiler"
  dependency-version: 20.3.18
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the title Bump @angular/compiler from 20.3.16 to 20.3.18 Bump @angular/compiler from 20.3.14 to 20.3.18 Apr 6, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/angular/compiler-20.3.18 branch from ec7fbdb to a6bee19 Compare April 6, 2026 20:25
@amontenegro amontenegro merged commit 2990061 into main Apr 6, 2026
6 checks passed
@dependabot dependabot bot deleted the dependabot/npm_and_yarn/angular/compiler-20.3.18 branch April 6, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant