This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/release/v1.3/pr-8622-1736427c57a64457385fa7b47989f157837da124
in repository https://gitbox.apache.org/repos/asf/texera.git

commit 0f3192ea416e151ef73682e9aee33c878f79096f
Author: Meng Wang <[email protected]>
AuthorDate: Mon Sep 21 20:07:54 2026 +0000

    fix(deps, frontend, v1.3): update dependency @angular/core to v21.2.20 
(#8622)
    
    ### What changes were proposed in this PR?
    
    Backport of #8494 to `release/v1.3`: a clean cherry-pick of its squash
    commit, no adaptations — three files, `frontend/package.json`,
    `frontend/yarn.lock` and `frontend/LICENSE-binary`.
    
    `@angular/core` 21.2.19 → 21.2.20 fixes CVE-2026-88057
    (GHSA-hh8m-fm6v-7cvg). This branch is still on 21.2.19, so v1.3 would
    ship with it unpatched. `@angular/common` and `@angular/compiler` stay
    at 21.2.19 here, exactly as on `main`; their own bumps are #8492 and
    #8493, still open.
    
    Opened manually by the v1.3 release manager: the automated fast path
    cherry-picked this cleanly and then pushed it straight to
    `release/v1.3`, where the Merge Queue ruleset rejected the push
    (`GH013`, [run
    35293784997](https://github.com/apache/texera/actions/runs/35293784997)).
    The Actions-app bypass meant to unblock that path (#8379) was never
    created — asfyaml rejects an `Integration` bypass actor — and the
    failing job's notification 403s for want of `pull-requests: write`, so
    the loss left neither a backport PR nor a comment on #8494. The
    `release/v1.2` backport did get a PR (#8584, still draft) only because
    its cherry-pick conflicted and so took the other code path. See #8377.
    
    Source: 8284b4280c4cd988a4b072900fb7dca7b89cf56b
    
    ### Any related issues, documentation, discussions?
    
    Backport of #8494.
    
    ### How was this PR tested?
    
    The change is a dependency bump identical to #8494; the backport tree is
    verified byte-identical to cherry-picking the squash commit onto
    `release/v1.3`, and the resulting `frontend/package.json` reads
    `"@angular/core": "21.2.20"`. Release-branch CI runs the frontend matrix
    on this PR.
    
    ### Was this PR authored or co-authored using generative AI tooling?
    
    Yes. Generated-by: Claude Code (claude-opus-5)
    
    Co-authored-by: Mend Renovate <[email protected]>
    Co-authored-by: Xuan Gu <[email protected]>
---
 frontend/LICENSE-binary |  2 +-
 frontend/package.json   |  2 +-
 frontend/yarn.lock      | 12 ++++++------
 3 files changed, 8 insertions(+), 8 deletions(-)

diff --git a/frontend/LICENSE-binary b/frontend/LICENSE-binary
index a2c99bfa9d..a0c75cfb81 100644
--- a/frontend/LICENSE-binary
+++ b/frontend/LICENSE-binary
@@ -252,7 +252,7 @@ Angular / npm packages:
   - @angular/[email protected]
   - @angular/[email protected]
   - @angular/[email protected]
-  - @angular/[email protected]
+  - @angular/[email protected]
   - @angular/[email protected]
   - @angular/[email protected]
   - @angular/[email protected]
diff --git a/frontend/package.json b/frontend/package.json
index bc825b471d..1a350f465b 100644
--- a/frontend/package.json
+++ b/frontend/package.json
@@ -26,7 +26,7 @@
     "@angular/cdk": "21.2.14",
     "@angular/common": "21.2.19",
     "@angular/compiler": "21.2.19",
-    "@angular/core": "21.2.19",
+    "@angular/core": "21.2.20",
     "@angular/forms": "21.2.18",
     "@angular/localize": "21.2.18",
     "@angular/platform-browser": "21.2.18",
diff --git a/frontend/yarn.lock b/frontend/yarn.lock
index 90a7341cdc..01dd2145a2 100644
--- a/frontend/yarn.lock
+++ b/frontend/yarn.lock
@@ -990,13 +990,13 @@ __metadata:
   languageName: node
   linkType: hard
 
-"@angular/core@npm:21.2.19":
-  version: 21.2.19
-  resolution: "@angular/core@npm:21.2.19"
+"@angular/core@npm:21.2.20":
+  version: 21.2.20
+  resolution: "@angular/core@npm:21.2.20"
   dependencies:
     tslib: "npm:^2.3.0"
   peerDependencies:
-    "@angular/compiler": 21.2.19
+    "@angular/compiler": 21.2.20
     rxjs: ^6.5.3 || ^7.4.0
     zone.js: ~0.15.0 || ~0.16.0
   peerDependenciesMeta:
@@ -1004,7 +1004,7 @@ __metadata:
       optional: true
     zone.js:
       optional: true
-  checksum: 
10c0/a060ee271acb93b5a633e5ab66bdf8fc6d13d17782b25d381ec51c5d664778de740d661b17ea36175a15d286422ad96760c1c0accf8b44a1ad6175d38869a7fd
+  checksum: 
10c0/8827cc0b8a8cc1beebed43244fce103259776dfe68dd0755d04bcd7fc2b76e1eecdfdad33798dfeb4a5825f93746525f2901e9aa1a401d27e7a4189db5fd4a54
   languageName: node
   linkType: hard
 
@@ -10969,7 +10969,7 @@ __metadata:
     "@angular/common": "npm:21.2.19"
     "@angular/compiler": "npm:21.2.19"
     "@angular/compiler-cli": "npm:21.2.18"
-    "@angular/core": "npm:21.2.19"
+    "@angular/core": "npm:21.2.20"
     "@angular/forms": "npm:21.2.18"
     "@angular/localize": "npm:21.2.18"
     "@angular/platform-browser": "npm:21.2.18"

Reply via email to