Skip to content

Pythons/oncehub 108277#229

Merged
so-kaushal merged 2 commits intoqafrom
pythons/ONCEHUB-108277
Dec 4, 2025
Merged

Pythons/oncehub 108277#229
so-kaushal merged 2 commits intoqafrom
pythons/ONCEHUB-108277

Conversation

@so-kaushal
Copy link
Contributor

https://scheduleonce.atlassian.net/browse/ONCEHUB-108277
CVE-2025-66412 vulnerability found in package @angular/compiler in project knowledgeowl-angular

This pull request updates the package version and upgrades several dependencies to their latest compatible versions, ensuring improved compatibility and stability for the project.

Version bump:

  • Updated the package version from 5.1.4 to 5.1.5 in package.json, src/package.json, and src/package-lock.json. [1] [2] [3]

Dependency upgrades:

  • Upgraded various Angular dependencies in package.json to the latest patch versions (^20.3.12 and ^20.3.15), improving compatibility and security.
  • Updated ng-packagr dependency from 20.3.0 to ^20.3.2 in package.json.

@so-kaushal so-kaushal self-assigned this Dec 4, 2025
Copilot AI review requested due to automatic review settings December 4, 2025 10:44
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request addresses a security vulnerability (CVE-2025-66412) in @angular/compiler by upgrading Angular dependencies and bumps the package version from 5.1.4 to 5.1.5.

Key Changes:

  • Package version bumped from 5.1.4 to 5.1.5 across all package.json files
  • Angular dependencies upgraded from 20.3.0 to 20.3.12-20.3.15 patch versions
  • ng-packagr updated from 20.3.0 to ^20.3.2
  • Extensive transitive dependency updates reflected in package-lock.json

Reviewed changes

Copilot reviewed 2 out of 4 changed files in this pull request and generated no comments.

File Description
package.json Updated version to 5.1.5; upgraded Angular packages to 20.3.12-20.3.15; updated ng-packagr to ^20.3.2
package-lock.json Resolved dependency tree with Angular 20.3.12-20.3.15 and numerous transitive dependency updates
src/package.json Updated version to 5.1.5
src/package-lock.json Updated version to 5.1.5 in lockfile metadata
Files not reviewed (1)
  • src/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@so-kaushal so-kaushal merged commit 7092c25 into qa Dec 4, 2025
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants