Skip to content

chore(deps): bump @angular/platform-server from 20.3.21 to 20.3.30 in /js - #6331

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js/angular/platform-server-20.3.30
Open

chore(deps): bump @angular/platform-server from 20.3.21 to 20.3.30 in /js#6331
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/js/angular/platform-server-20.3.30

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 11, 2026

Copy link
Copy Markdown
Contributor

Bumps @angular/platform-server from 20.3.21 to 20.3.30.

Release notes

Sourced from @​angular/platform-server's releases.

20.3.30

platform-server

Commit Description
fix - 9339a7a2de avoid stripping unicode whitespace during url resolution
fix - 89b20568df update domino to latest version

20.3.29

platform-browser

Commit Description
fix - 7538744c10 disallow event handler attributes in Meta

20.3.28

core

Commit Description
fix - 2f96c8020f sanitize host bindings on concrete hosts

http

Commit Description
fix - 969133d426 match header values exactly when deleting
fix - 29dd26bd71 preserve immutability of materialized clones
fix - e4c416c20a run root interceptors in the terminal request chain

20.3.27

compiler

Commit Description
fix - 5dbcd0ee16 disallow i18n event attributes
fix - db0d4a1a39 restrict possible event handler check to property names longer than 2 characters

http

Commit Description
fix - a64e2883e9 distinguish repeated transfer cache params

platform-server

Commit Description
fix - 6f80cca0b8 update domino to latest version

20.3.26

compiler-cli

Commit Description
fix - 406aaa31e6 update babel dependencies to latest v7

core

Commit Description
fix - 26831d0cbd avoid caching missing locale data
fix - 8eb7aea08b reject dynamic script host elements

... (truncated)

Changelog

Sourced from @​angular/platform-server's changelog.

20.3.30 (2026-08-26)

platform-server

Commit Type Description
9339a7a2de fix avoid stripping unicode whitespace during url resolution
89b20568df fix update domino to latest version

20.3.29 (2026-08-19)

platform-browser

Commit Type Description
7538744c10 fix disallow event handler attributes in Meta

20.3.28 (2026-08-13)

core

Commit Type Description
2f96c8020f fix sanitize host bindings on concrete hosts

http

Commit Type Description
969133d426 fix match header values exactly when deleting
29dd26bd71 fix preserve immutability of materialized clones
e4c416c20a fix run root interceptors in the terminal request chain

20.3.27 (2026-07-29)

compiler

| Commit | Type | Description |

... (truncated)

Commits
  • 9339a7a fix(platform-server): avoid stripping unicode whitespace during url resolution
  • d55c94a refactor(platform-server): deprecate ServerXhr (#69256)
  • 49368c1 fix(platform-server): harden platform location origin validation during SSR
  • fc7ea0b refactor(platform-server): replace standard Error with RuntimeError
  • 6ca433e fix(platform-server): throw on suspicious URLs and restrict protocol-relative...
  • c99d9f0 refactor(platform-server): extract parseUrl regex and add comments for URL pa...
  • 49a60f6 fix(platform-server): secure location and document initialization against SSR...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [@angular/platform-server](https://github.com/angular/angular/tree/HEAD/packages/platform-server) from 20.3.21 to 20.3.30.
- [Release notes](https://github.com/angular/angular/releases)
- [Changelog](https://github.com/angular/angular/blob/v20.3.30/CHANGELOG.md)
- [Commits](https://github.com/angular/angular/commits/v20.3.30/packages/platform-server)

---
updated-dependencies:
- dependency-name: "@angular/platform-server"
  dependency-version: 20.3.30
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

config dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code js

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants