Skip to content

Conversation

chrux
Copy link

@chrux chrux commented Jun 5, 2025

PR Checklist

Please check to confirm your PR fulfills the following requirements:

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Build related changes
  • CI related changes
  • Documentation content changes
  • Other... Please describe: Fix security vulnerability

What is the current behavior?

Issue Number: N/A

What is the new behavior?

Does this PR introduce a breaking change?

  • Yes
  • No

Other information

@angular-robot angular-robot bot added the area: build & ci Related the build and CI infrastructure of the project label Jun 5, 2025
@alan-agius4 alan-agius4 added the target: lts This PR is targeting a version currently in long-term support label Jun 5, 2025
Copy link
Collaborator

@alan-agius4 alan-agius4 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There are a couple of instances "webpack-dev-server": "5.2.0" left, can you please update the version everywhere?

Also, please update the commit message to

fix(@angular-devkit/build-angular): update dependency webpack-dev-server to v5.2.2

Security update for more information see: https://github.com/webpack/webpack-dev-server/blob/master/CHANGELOG.md#521-2025-03-26

@alan-agius4 alan-agius4 added the action: cleanup The PR is in need of cleanup, either due to needing a rebase or in response to comments from reviews label Jun 5, 2025
@angular-robot angular-robot bot added area: @angular-devkit/build-angular and removed area: build & ci Related the build and CI infrastructure of the project labels Jun 5, 2025
@chrux
Copy link
Author

chrux commented Jun 5, 2025

@alan-agius4 done, let me know if anything else needs to be done

@alan-agius4 alan-agius4 removed the action: cleanup The PR is in need of cleanup, either due to needing a rebase or in response to comments from reviews label Jun 6, 2025
Copy link
Collaborator

@alan-agius4 alan-agius4 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks for your contribution.

@alan-agius4 alan-agius4 added severity6: security action: merge The PR is ready for merge by the caretaker labels Jun 6, 2025
@alan-agius4 alan-agius4 added the merge: caretaker note Alert the caretaker performing the merge to check the PR for an out of normal action needed or note label Jun 6, 2025
@alan-agius4
Copy link
Collaborator

**Caretaker note: ** the failure is due to mis matching Node.js versions. We should tackle this separately.

@dgp1130 dgp1130 merged commit b120e14 into angular:19.2.x Jun 6, 2025
29 of 31 checks passed
dgp1130 added a commit to dgp1130/angular-cli that referenced this pull request Jun 6, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](angular#30469).
@dgp1130
Copy link
Collaborator

dgp1130 commented Jun 6, 2025

v18 port of this change in #30487.

dgp1130 added a commit to dgp1130/angular-cli that referenced this pull request Jun 6, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](angular#30469).
dgp1130 added a commit to dgp1130/angular-cli that referenced this pull request Jun 6, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](angular#30469).
dgp1130 added a commit to dgp1130/angular-cli that referenced this pull request Jun 10, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](angular#30469).
dgp1130 added a commit to dgp1130/angular-cli that referenced this pull request Jun 10, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](angular#30469).
clydin pushed a commit that referenced this pull request Jun 10, 2025
v18 port of [`b120e1411c28c99defb34274a11f0fb54972178a`](#30469).
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Jul 7, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
action: merge The PR is ready for merge by the caretaker area: @angular-devkit/build-angular merge: caretaker note Alert the caretaker performing the merge to check the PR for an out of normal action needed or note severity6: security target: lts This PR is targeting a version currently in long-term support
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants