dependabot[bot] opened a new pull request, #27769:
URL: https://github.com/apache/flink/pull/27769

   Bumps 
[@angular/core](https://github.com/angular/angular/tree/HEAD/packages/core) 
from 20.1.3 to 20.3.18.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/angular/angular/releases";><code>@​angular/core</code>'s
 releases</a>.</em></p>
   <blockquote>
   <h2>20.3.18</h2>
   <h3>compiler</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/02fbf08890ec6ac2efb6c2ec4f17e56497cb81d2";><img
 src="https://img.shields.io/badge/02fbf08890-fix-green"; alt="fix - 02fbf08890" 
/></a></td>
   <td>disallow translations of iframe src</td>
   </tr>
   </tbody>
   </table>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/72126f9a08c185a9b93461bab67841c4e84c9b17";><img
 src="https://img.shields.io/badge/72126f9a08-fix-green"; alt="fix - 72126f9a08" 
/></a></td>
   <td>sanitize translated attribute bindings with interpolations</td>
   </tr>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/626bc8bc20e485cad2094c4a5d9417fb9a71dda8";><img
 src="https://img.shields.io/badge/626bc8bc20-fix-green"; alt="fix - 626bc8bc20" 
/></a></td>
   <td>sanitize translated form attributes</td>
   </tr>
   </tbody>
   </table>
   <h2>20.3.17</h2>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/7f9de3c118383c09fa8851708c66ec94453a9680";><img
 src="https://img.shields.io/badge/7f9de3c118-fix-green"; alt="fix - 7f9de3c118" 
/></a></td>
   <td>block creation of sensitive URI attributes from ICU messages</td>
   </tr>
   </tbody>
   </table>
   <h2>Breaking Changes</h2>
   <h3>core</h3>
   <ul>
   <li>
   <p>Angular now only applies known attributes from HTML in translated ICU 
content. Unknown attributes are dropped and not rendered.</p>
   <p>(cherry picked from commit 03da204b6daa5e4583e0d0968c2107390bbd8235)</p>
   </li>
   </ul>
   <h2>20.3.16</h2>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/c2c2b4aaa84c67d2eccd4ef4f94b5ea444a7f73a";><img
 src="https://img.shields.io/badge/c2c2b4aaa8-fix-green"; alt="fix - c2c2b4aaa8" 
/></a></td>
   <td>sanitize sensitive attributes on SVG script elements</td>
   </tr>
   </tbody>
   </table>
   <h2>20.3.15</h2>
   <h3>compiler</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/d1ca8ae04390f050039fdb653a6147d75d48f81e";><img
 src="https://img.shields.io/badge/d1ca8ae043-fix-green"; alt="fix - d1ca8ae043" 
/></a></td>
   <td>prevent XSS via SVG animation <code>attributeName</code> and MathML/SVG 
URLs</td>
   </tr>
   </tbody>
   </table>
   <h2>20.3.14</h2>
   <h3>http</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/0276479e7d0e280e0f8d26fa567d3b7aa97a516f";><img
 src="https://img.shields.io/badge/0276479e7d-fix-green"; alt="fix - 0276479e7d" 
/></a></td>
   <td>prevent XSRF token leakage to protocol-relative URLs</td>
   </tr>
   </tbody>
   </table>
   <h2>20.3.13</h2>
   <p>No release notes provided.</p>
   <h2>20.3.12</h2>
   <p>No release notes provided.</p>
   <h2>20.3.11</h2>
   <h3>common</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Description</th>
   </tr>
   </thead>
   </table>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/angular/angular/blob/main/CHANGELOG.md";><code>@​angular/core</code>'s
 changelog</a>.</em></p>
   <blockquote>
   <h1>20.3.18 (2026-03-12)</h1>
   <h3>compiler</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/02fbf08890ec6ac2efb6c2ec4f17e56497cb81d2";>02fbf08890</a></td>
   <td>fix</td>
   <td>disallow translations of iframe src</td>
   </tr>
   </tbody>
   </table>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/72126f9a08c185a9b93461bab67841c4e84c9b17";>72126f9a08</a></td>
   <td>fix</td>
   <td>sanitize translated attribute bindings with interpolations</td>
   </tr>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/626bc8bc20e485cad2094c4a5d9417fb9a71dda8";>626bc8bc20</a></td>
   <td>fix</td>
   <td>sanitize translated form attributes</td>
   </tr>
   </tbody>
   </table>
   <!-- raw HTML omitted -->
   <p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
   <h1>22.0.0-next.3 (2026-03-12)</h1>
   <h3>compiler</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/78dea55351fb305b33a919c43a6b363137eca166";>78dea55351</a></td>
   <td>fix</td>
   <td>disallow translations of iframe src</td>
   </tr>
   </tbody>
   </table>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/999c14eaab981d12bf2b1d9b1fd6766157f7b1cc";>999c14eaab</a></td>
   <td>fix</td>
   <td>reverts &quot;feat(core): add support for nested animations&quot;</td>
   </tr>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/de0eb4c6566011e1a34d529a273ec3d5b6bf17d5";>de0eb4c656</a></td>
   <td>fix</td>
   <td>sanitize translated form attributes</td>
   </tr>
   </tbody>
   </table>
   <!-- raw HTML omitted -->
   <p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
   <h1>21.2.4 (2026-03-12)</h1>
   <h3>compiler</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/ed2d324f9cc12aab6cfa0569ef10b73243a62c65";>ed2d324f9c</a></td>
   <td>fix</td>
   <td>disallow translations of iframe src</td>
   </tr>
   </tbody>
   </table>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/abbd8797bbd3ae53a10033c39bd895b5b85a4fae";>abbd8797bb</a></td>
   <td>fix</td>
   <td>reverts &quot;feat(core): add support for nested animations&quot;</td>
   </tr>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/d1dcd16c5b40291aa3fa2dc84d22842cd657b201";>d1dcd16c5b</a></td>
   <td>fix</td>
   <td>sanitize translated form attributes</td>
   </tr>
   </tbody>
   </table>
   <!-- raw HTML omitted -->
   <p><!-- raw HTML omitted --><!-- raw HTML omitted --></p>
   <h1>22.0.0-next.2 (2026-03-11)</h1>
   <h2>Breaking Changes</h2>
   <h3>core</h3>
   <ul>
   <li><code>createNgModuleRef</code> was removed, use 
<code>createNgModule</code> instead</li>
   </ul>
   <h3>core</h3>
   <table>
   <thead>
   <tr>
   <th>Commit</th>
   <th>Type</th>
   <th>Description</th>
   </tr>
   </thead>
   <tbody>
   <tr>
   <td><a 
href="https://github.com/angular/angular/commit/b918beda323eefef17bf1de03fde3d402a3d4af0";>b918beda32</a></td>
   <td>feat</td>
   <td>allow debouncing signals</td>
   </tr>
   </tbody>
   </table>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/angular/angular/commit/626bc8bc20e485cad2094c4a5d9417fb9a71dda8";><code>626bc8b</code></a>
 fix(core): sanitize translated form attributes</li>
   <li><a 
href="https://github.com/angular/angular/commit/72126f9a08c185a9b93461bab67841c4e84c9b17";><code>72126f9</code></a>
 fix(core): sanitize translated attribute bindings with interpolations</li>
   <li><a 
href="https://github.com/angular/angular/commit/7f9de3c118383c09fa8851708c66ec94453a9680";><code>7f9de3c</code></a>
 fix(core): block creation of sensitive URI attributes from ICU messages</li>
   <li><a 
href="https://github.com/angular/angular/commit/c2c2b4aaa84c67d2eccd4ef4f94b5ea444a7f73a";><code>c2c2b4a</code></a>
 fix(core): sanitize sensitive attributes on SVG script elements</li>
   <li><a 
href="https://github.com/angular/angular/commit/d1ca8ae04390f050039fdb653a6147d75d48f81e";><code>d1ca8ae</code></a>
 fix(compiler): prevent XSS via SVG animation <code>attributeName</code> and 
MathML/SVG URLs</li>
   <li><a 
href="https://github.com/angular/angular/commit/820bb3991c907384e656cc71b9483fe552ddb602";><code>820bb39</code></a>
 Revert &quot;refactor(core): let the profiler handle asymmetric events 
leniently&quot;</li>
   <li><a 
href="https://github.com/angular/angular/commit/2dccdcd6bc7708825294f0ab52bd0680f4318fcd";><code>2dccdcd</code></a>
 Revert &quot;fix(core): notify profiler events in case of errors&quot;</li>
   <li><a 
href="https://github.com/angular/angular/commit/a966ff18d49c674ca0467d493473c90be969e1a6";><code>a966ff1</code></a>
 refactor(core): let the profiler handle asymmetric events leniently</li>
   <li><a 
href="https://github.com/angular/angular/commit/52cf65892a29d4e863e916bb7e9d890aad402882";><code>52cf658</code></a>
 fix(core): notify profiler events in case of errors</li>
   <li><a 
href="https://github.com/angular/angular/commit/daae2636d5ed221fc84b0dbaa67fe26198015f71";><code>daae263</code></a>
 docs: Adds links to relevant guides for APIs in core package</li>
   <li>Additional commits viewable in <a 
href="https://github.com/angular/angular/commits/v20.3.18/packages/core";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@angular/core&package-manager=npm_and_yarn&previous-version=20.1.3&new-version=20.3.18)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/flink/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to