The GitHub Actions job "Required Checks" on 
texera.git/backport/8494-update-dependency-angular-core-to-v21-2-v1.2 has 
succeeded.
Run started by GitHub user xuang7 (triggered by xuang7).

Head commit for run:
eba7581b31d556a5a6729835766a0e7185dbf02d / Mend Renovate <[email protected]>
fix(deps, frontend): update dependency @angular/core to v21.2.20 (#8494)

This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@angular/core](https://redirect.github.com/angular/angular)
([source](https://redirect.github.com/angular/angular/tree/HEAD/packages/core))
| [`21.2.19` →
`21.2.20`](https://renovatebot.com/diffs/npm/@angular%2fcore/21.2.19/21.2.20)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@angular%2fcore/21.2.20?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@angular%2fcore/21.2.19/21.2.20?slim=true)
|

---

host elements in @&#8203;angular/core and @&#8203;angular/compiler
[CVE-2026-88057](https://nvd.nist.gov/vuln/detail/CVE-2026-88057) /
[GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)

<details>
<summary>More information</summary>

Angular automatically sanitizes untrusted values bound to
security-sensitive DOM sinks (such as `href`, `src`, `action`,
`xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).

Prior to the fix, the Angular compiler determined the `SecurityContext`
for directive host bindings (`host: {'[attr.href]': 'value'}` or
`@HostBinding('attr.href')`) based solely on the declaring directive or
component selector at compile time, rather than the concrete host
element that the directive was applied to.

When a directive with a security-sensitive host binding was applied to a
different concrete host element—such as through:
- `hostDirectives` composition,
- Class inheritance of host bindings,
- Dynamic component instantiation (`createComponent` with custom
`hostElement` or dynamic directives),
- Elements with SVG/MathML namespaces (e.g. `<svg:a>`, `<math>`), or
- Elements using tag-neutral selectors (e.g. `:not(...)`),

the compiler either failed to associate a sanitizer with the host
binding or attached an incorrect security context. As a result,
untrusted inputs (e.g. `javascript:...` URLs) bound via the host binding
would be written to the DOM attribute without passing through Angular's
built-in sanitizer.

An attacker capable of controlling the value bound to an affected
directive host binding could execute arbitrary JavaScript in the user's
browser context (Cross-Site Scripting).

This issue has been resolved in versions:
- `22.1.0`
- `21.2.20`
- `20.3.28`

Ensure that any user-controlled values assigned to properties bound via
directive host bindings are explicitly sanitized using
`DomSanitizer.sanitize(SecurityContext.URL, ...)` before assignment, or
restrict the input to validated safe URL schemes (e.g. `http://`,
`https://`).

- CVSS Score: 5.3 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N`

-
[https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg)
-
[https://github.com/angular/angular/issues/69550](https://redirect.github.com/angular/angular/issues/69550)
-
[https://github.com/angular/angular/pull/69558](https://redirect.github.com/angular/angular/pull/69558)
-
[https://github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264](https://redirect.github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264)
-
[https://github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
-
[https://github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b](https://redirect.github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b)
-
[https://github.com/angular/angular/releases/tag/v20.3.28](https://redirect.github.com/angular/angular/releases/tag/v20.3.28)
-
[https://github.com/angular/angular/releases/tag/v21.2.20](https://redirect.github.com/angular/angular/releases/tag/v21.2.20)
-
[https://github.com/angular/angular/releases/tag/v22.1.0](https://redirect.github.com/angular/angular/releases/tag/v22.1.0)
-
[https://github.com/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)

This data is provided by the [GitHub Advisory
Database](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

host elements in @&#8203;angular/core and @&#8203;angular/compiler
[CVE-2026-88057](https://nvd.nist.gov/vuln/detail/CVE-2026-88057) /
[GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/advisories/GHSA-hh8m-fm6v-7cvg)

<details>
<summary>More information</summary>

Angular automatically sanitizes untrusted values bound to
security-sensitive DOM sinks (such as `href`, `src`, `action`,
`xlink:href`, and `data`) to protect against Cross-Site Scripting (XSS).

Prior to the fix, the Angular compiler determined the `SecurityContext`
for directive host bindings (`host: {'[attr.href]': 'value'}` or
`@HostBinding('attr.href')`) based solely on the declaring directive or
component selector at compile time, rather than the concrete host
element that the directive was applied to.

When a directive with a security-sensitive host binding was applied to a
different concrete host element—such as through:
- `hostDirectives` composition,
- Class inheritance of host bindings,
- Dynamic component instantiation (`createComponent` with custom
`hostElement` or dynamic directives),
- Elements with SVG/MathML namespaces (e.g. `<svg:a>`, `<math>`), or
- Elements using tag-neutral selectors (e.g. `:not(...)`),

the compiler either failed to associate a sanitizer with the host
binding or attached an incorrect security context. As a result,
untrusted inputs (e.g. `javascript:...` URLs) bound via the host binding
would be written to the DOM attribute without passing through Angular's
built-in sanitizer.

An attacker capable of controlling the value bound to an affected
directive host binding could execute arbitrary JavaScript in the user's
browser context (Cross-Site Scripting).

This issue has been resolved in versions:
- `22.1.0`
- `21.2.20`
- `20.3.28`

Ensure that any user-controlled values assigned to properties bound via
directive host bindings are explicitly sanitized using
`DomSanitizer.sanitize(SecurityContext.URL, ...)` before assignment, or
restrict the input to validated safe URL schemes (e.g. `http://`,
`https://`).

- CVSS Score: 5.3 / 10 (Medium)
- Vector String:
`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N`

-
[https://github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg](https://redirect.github.com/angular/angular/security/advisories/GHSA-hh8m-fm6v-7cvg)
-
[https://github.com/angular/angular/issues/69550](https://redirect.github.com/angular/angular/issues/69550)
-
[https://github.com/angular/angular/pull/69558](https://redirect.github.com/angular/angular/pull/69558)
-
[https://github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264](https://redirect.github.com/angular/angular/commit/2f96c8020f85ccb715a76de4b79a0c680c2c7264)
-
[https://github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
-
[https://github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b](https://redirect.github.com/angular/angular/commit/6caa298dee58319b2d674dc91364e26ffe3ecb2b)
-
[https://github.com/angular/angular](https://redirect.github.com/angular/angular)
-
[https://github.com/angular/angular/releases/tag/v20.3.28](https://redirect.github.com/angular/angular/releases/tag/v20.3.28)
-
[https://github.com/angular/angular/releases/tag/v21.2.20](https://redirect.github.com/angular/angular/releases/tag/v21.2.20)
-
[https://github.com/angular/angular/releases/tag/v22.1.0](https://redirect.github.com/angular/angular/releases/tag/v22.1.0)

This data is provided by
[OSV](https://osv.dev/vulnerability/GHSA-hh8m-fm6v-7cvg) and the [GitHub
Advisory Database](https://redirect.github.com/github/advisory-database)
([CC-BY
4.0](https://redirect.github.com/github/advisory-database/blob/main/LICENSE.md)).
</details>

---

<details>
<summary>angular/angular (@&#8203;angular/core)</summary>

[`v21.2.20`](https://redirect.github.com/angular/angular/blob/HEAD/CHANGELOG.md#21220-2026-08-12)

[Compare
Source](https://redirect.github.com/angular/angular/compare/v21.2.19...v21.2.20)

| Commit | Type | Description |
|
------------------------------------------------------------------------------------------------
| ---- | ---------------------------------------- |
|
[6afe6fa781](https://redirect.github.com/angular/angular/commit/6afe6fa781c2f0931f0aedd729b9884a8fe212ee)
| fix | sanitize host bindings on concrete hosts |

| Commit | Type | Description |
|
------------------------------------------------------------------------------------------------
| ---- | --------------------------------------------------- |
|
[fec5977df4](https://redirect.github.com/angular/angular/commit/fec5977df4dda3a10d5ce2923e3e06d86ba11ee7)
| fix | match header values exactly when deleting |
|
[e33d69a71c](https://redirect.github.com/angular/angular/commit/e33d69a71c5beb8fe5785b53fd6b37658334e8e0)
| fix | preserve immutability of materialized clones |
|
[caf616670f](https://redirect.github.com/angular/angular/commit/caf616670fd20d528aa69e0131cc17d60f0cc27d)
| fix | run root interceptors in the terminal request chain |

<!-- CHANGELOG SPLIT MARKER -->

</details>

---

📅 **Schedule**: (in timezone Etc/UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/apache/texera).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43OS4xIiwidXBkYXRlZEluVmVyIjoiNDQuNzkuMSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZGVwZW5kZW5jaWVzIiwicmVsZWFzZS92MS4yIiwic2VjdXJpdHkiXX0=-->

---------

Co-authored-by: mengw15 <[email protected]>
Co-authored-by: Xuan Gu <[email protected]>
(cherry picked from commit 8284b4280c4cd988a4b072900fb7dca7b89cf56b)

Report URL: https://github.com/apache/texera/actions/runs/36047482800

With regards,
GitHub Actions via GitBox

Reply via email to