This is an automated email from the ASF dual-hosted git repository.

github-merge-queue[bot] pushed a commit to branch 
gh-readonly-queue/main/pr-8493-4f670fc9ec70af7315c45489fb7a025f881982ec
in repository https://gitbox.apache.org/repos/asf/texera.git

commit 10792779f71ab8805b1ef3448e87f24239cd6516
Author: Mend Renovate <[email protected]>
AuthorDate: Wed Sep 23 07:50:18 2026 +0000

    fix(deps, frontend): update dependency @angular/compiler to v21.2.20 (#8493)
    
    This PR contains the following updates:
    
    | Package | Change |
    [Age](https://docs.renovatebot.com/merge-confidence/) |
    [Confidence](https://docs.renovatebot.com/merge-confidence/) |
    |---|---|---|---|
    | [@angular/compiler](https://redirect.github.com/angular/angular)
    
([source](https://redirect.github.com/angular/angular/tree/HEAD/packages/compiler))
    | [`21.2.19` →
    
`21.2.20`](https://renovatebot.com/diffs/npm/@angular%2fcompiler/21.2.19/21.2.20)
    |
    
![age](https://developer.mend.io/api/mc/badges/age/npm/@angular%2fcompiler/21.2.20?slim=true)
    |
    
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@angular%2fcompiler/21.2.19/21.2.20?slim=true)
    |
    
    ---
    
    ### Angular: Sanitization bypass via directive host bindings on concrete
    host elements in @&#8203;angular/core and @&#8203;angular/compiler
    [CVE-2026-88057](https://nvd.nist.gov/vuln/detail/CVE-2026-88057) /
    
[GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)
    
    <details>
    <summary>More information</summary>
    
    #### Details
    Angular automatically sanitizes untrusted values bound to
    security-sensitive DOM sinks (such as `href`, `src`, `action`,
    `xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).
    
    Prior to the fix, the Angular compiler determined the `SecurityContext`
    for directive host bindings (`host: {'[attr.href]': 'value'}` or
    `@HostBinding('attr.href')`) based solely on the declaring directive or
    component selector at compile time, rather than the concrete host
    element that the directive was applied to.
    
    When a directive with a security-sensitive host binding was applied to a
    different concrete host element—such as through:
    - `hostDirectives` composition,
    - Class inheritance of host bindings,
    - Dynamic component instantiation (`createComponent` with custom
    `hostElement` or dynamic directives),
    - Elements with SVG/MathML namespaces (e.g. `<svg:a>`, `<math>`), or
    - Elements using tag-neutral selectors (e.g. `:not(...)`),
    
    the compiler either failed to associate a sanitizer with the host
    binding or attached an incorrect security context. As a result,
    untrusted inputs (e.g. `javascript:...` URLs) bound via the host binding
    would be written to the DOM attribute without passing through Angular's
    built-in sanitizer.
    
    ##### Impact
    An attacker capable of controlling the value bound to an affected
    directive host binding could execute arbitrary JavaScript in the user's
    browser context (Cross-Site Scripting).
    
    ##### Patches
    This issue has been resolved in versions:
    - `22.1.0`
    - `21.2.20`
    - `20.3.28`
    
    ##### Workarounds
    Ensure that any user-controlled values assigned to properties bound via
    directive host bindings are explicitly sanitized using
    `DomSanitizer.sanitize(SecurityContext.URL, ...)` before assignment, or
    restrict the input to validated safe URL schemes (e.g. `http://`,
    `https://`).
    
    #### Severity
    - CVSS Score: 5.3 / 10 (Medium)
    - Vector String:
    `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N`
    
    #### References
    -
    
[https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg)
    -
    
[https://github.com/angular/angular/issues/69550](https://redirect.github.com/angular/angular/issues/69550)
    -
    
[https://github.com/angular/angular/pull/69558](https://redirect.github.com/angular/angular/pull/69558)
    -
    
[https://github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264](https://redirect.github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264)
    -
    
[https://github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
    -
    
[https://github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b](https://redirect.github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b)
    -
    
[https://github.com/angular/angular/releases/tag/v20.3.28](https://redirect.github.com/angular/angular/releases/tag/v20.3.28)
    -
    
[https://github.com/angular/angular/releases/tag/v21.2.20](https://redirect.github.com/angular/angular/releases/tag/v21.2.20)
    -
    
[https://github.com/angular/angular/releases/tag/v22.1.0](https://redirect.github.com/angular/angular/releases/tag/v22.1.0)
    -
    
[https://github.com/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)
    
    This data is provided by the [GitHub Advisory
    Database](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)
    ([CC-BY
    
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
    </details>
    
    ---
    
    ### Angular: Sanitization bypass via directive host bindings on concrete
    host elements in @&#8203;angular/core and @&#8203;angular/compiler
    [CVE-2026-88057](https://nvd.nist.gov/vuln/detail/CVE-2026-88057) /
    
[GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)
    
    <details>
    <summary>More information</summary>
    
    #### Details
    Angular automatically sanitizes untrusted values bound to
    security-sensitive DOM sinks (such as `href`, `src`, `action`,
    `xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).
    
    Prior to the fix, the Angular compiler determined the `SecurityContext`
    for directive host bindings (`host: {'[attr.href]': 'value'}` or
    `@HostBinding('attr.href')`) based solely on the declaring directive or
    component selector at compile time, rather than the concrete host
    element that the directive was applied to.
    
    When a directive with a security-sensitive host binding was applied to a
    different concrete host element—such as through:
    - `hostDirectives` composition,
    - Class inheritance of host bindings,
    - Dynamic component instantiation (`createComponent` with custom
    `hostElement` or dynamic directives),
    - Elements with SVG/MathML namespaces (e.g. `<svg:a>`, `<math>`), or
    - Elements using tag-neutral selectors (e.g. `:not(...)`),
    
    the compiler either failed to associate a sanitizer with the host
    binding or attached an incorrect security context. As a result,
    untrusted inputs (e.g. `javascript:...` URLs) bound via the host binding
    would be written to the DOM attribute without passing through Angular's
    built-in sanitizer.
    
    ##### Impact
    An attacker capable of controlling the value bound to an affected
    directive host binding could execute arbitrary JavaScript in the user's
    browser context (Cross-Site Scripting).
    
    ##### Patches
    This issue has been resolved in versions:
    - `22.1.0`
    - `21.2.20`
    - `20.3.28`
    
    ##### Workarounds
    Ensure that any user-controlled values assigned to properties bound via
    directive host bindings are explicitly sanitized using
    `DomSanitizer.sanitize(SecurityContext.URL, ...)` before assignment, or
    restrict the input to validated safe URL schemes (e.g. `http://`,
    `https://`).
    
    #### Severity
    - CVSS Score: 5.3 / 10 (Medium)
    - Vector String:
    `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N`
    
    #### References
    -
    
[https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg)
    -
    
[https://github.com/angular/angular/issues/69550](https://redirect.github.com/angular/angular/issues/69550)
    -
    
[https://github.com/angular/angular/pull/69558](https://redirect.github.com/angular/angular/pull/69558)
    -
    
[https://github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264](https://redirect.github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264)
    -
    
[https://github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
    -
    
[https://github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b](https://redirect.github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b)
    -
    
[https://github.com/angular/angular](https://redirect.github.com/angular/angular)
    -
    
[https://github.com/angular/angular/releases/tag/v20.3.28](https://redirect.github.com/angular/angular/releases/tag/v20.3.28)
    -
    
[https://github.com/angular/angular/releases/tag/v21.2.20](https://redirect.github.com/angular/angular/releases/tag/v21.2.20)
    -
    
[https://github.com/angular/angular/releases/tag/v22.1.0](https://redirect.github.com/angular/angular/releases/tag/v22.1.0)
    
    This data is provided by
    [OSV](https://osv.dev/vulnerability/GHSA-hh8m-fm6v-7cvg) and the [GitHub
    Advisory Database](https://redirect.github.com/github/advisory-database)
    ([CC-BY
    
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
    </details>
    
    ---
    
    ### Release Notes
    
    <details>
    <summary>angular/angular (@&#8203;angular/compiler)</summary>
    
    ###
    
[`v21.2.20`](https://redirect.github.com/angular/angular/blob/HEAD/CHANGELOG.md#21220-2026-08-12)
    
    [Compare
    
Source](https://redirect.github.com/angular/angular/compare/v21.2.19...v21.2.20)
    
    ##### core
    
    | Commit | Type | Description |
    |
    
------------------------------------------------------------------------------------------------
    | ---- | ---------------------------------------- |
    |
    
[6afe6fa781](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
    | fix | sanitize host bindings on concrete hosts |
    
    ##### http
    
    | Commit | Type | Description |
    |
    
------------------------------------------------------------------------------------------------
    | ---- | --------------------------------------------------- |
    |
    
[fec5977df4](https://redirect.github.com/angular/angular/commit/fec5977df4dda3a10d5ce2923e3e06d86ba11ee7)
    | fix | match header values exactly when deleting |
    |
    
[e33d69a71c](https://redirect.github.com/angular/angular/commit/e33d69a71c5beb8fe5785b53fd6b37658334e8e0)
    | fix | preserve immutability of materialized clones |
    |
    
[caf616670f](https://redirect.github.com/angular/angular/commit/caf616670fd20d528aa69e0131cc17d60f0cc27d)
    | fix | run root interceptors in the terminal request chain |
    
    <!-- CHANGELOG SPLIT MARKER -->
    
    </details>
    
    ---
    
    ### Configuration
    
    📅 **Schedule**: (in timezone Etc/UTC)
    
    - Branch creation
      - At any time (no schedule defined)
    - Automerge
      - At any time (no schedule defined)
    
    🚦 **Automerge**: Disabled by config. Please merge this manually once you
    are satisfied.
    
    ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
    rebase/retry checkbox.
    
    🔕 **Ignore**: Close this PR and you won't be reminded about this update
    again.
    
    ---
    
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
    this box
    
    ---
    
    This PR was generated by [Mend Renovate](https://mend.io/renovate/).
    View the [repository job
    log](https://developer.mend.io/github/apache/texera).
    
    
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43OS4xIiwidXBkYXRlZEluVmVyIjoiNDQuNzkuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwicmVsZWFzZS92MS4yIiwic2VjdXJpdHkiXX0=-->
    
    Co-authored-by: Meng Wang <[email protected]>
    Co-authored-by: Xuan Gu <[email protected]>
    Co-authored-by: mengw15 <[email protected]>
---
 frontend/package.json |  2 +-
 frontend/yarn.lock    | 10 +++++-----
 2 files changed, 6 insertions(+), 6 deletions(-)

diff --git a/frontend/package.json b/frontend/package.json
index 6290cd76aa..a01e97cef4 100644
--- a/frontend/package.json
+++ b/frontend/package.json
@@ -25,7 +25,7 @@
     "@angular/animations": "21.2.18",
     "@angular/cdk": "21.2.14",
     "@angular/common": "21.2.19",
-    "@angular/compiler": "21.2.19",
+    "@angular/compiler": "21.2.20",
     "@angular/core": "21.2.20",
     "@angular/forms": "21.2.18",
     "@angular/localize": "21.2.18",
diff --git a/frontend/yarn.lock b/frontend/yarn.lock
index d4ed345093..77f5add04b 100644
--- a/frontend/yarn.lock
+++ b/frontend/yarn.lock
@@ -744,12 +744,12 @@ __metadata:
   languageName: node
   linkType: hard
 
-"@angular/compiler@npm:21.2.19":
-  version: 21.2.19
-  resolution: "@angular/compiler@npm:21.2.19"
+"@angular/compiler@npm:21.2.20":
+  version: 21.2.20
+  resolution: "@angular/compiler@npm:21.2.20"
   dependencies:
     tslib: "npm:^2.3.0"
-  checksum: 
10c0/ae3993ed73a4731e1ccd84518fc20520273e6afd38cc040af0ef423c0b60d57fd4a72dbfb955009e6bb67a4119cd118d2fc82486e0b17924ce7f35ce0037da2f
+  checksum: 
10c0/5c1ea9f3a43420897d7373b9701b78889f85c98f8397476ece105295b50ea01a41342ea9df2aae1190919c33cb428853acfbe217c856cb098f051b45aa877a0f
   languageName: node
   linkType: hard
 
@@ -10719,7 +10719,7 @@ __metadata:
     "@angular/cdk": "npm:21.2.14"
     "@angular/cli": "npm:21.2.19"
     "@angular/common": "npm:21.2.19"
-    "@angular/compiler": "npm:21.2.19"
+    "@angular/compiler": "npm:21.2.20"
     "@angular/compiler-cli": "npm:21.2.18"
     "@angular/core": "npm:21.2.20"
     "@angular/forms": "npm:21.2.18"

Reply via email to