Skip to content

Bump picomatch, @angular-devkit/build-angular and @angular/cli#28

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-7d9b378be5
Open

Bump picomatch, @angular-devkit/build-angular and @angular/cli#28
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-7d9b378be5

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 2, 2026

Bumps picomatch to 2.3.2 and updates ancestor dependencies picomatch, @angular-devkit/build-angular and @angular/cli. These dependencies need to be updated together.

Updates picomatch from 2.3.1 to 2.3.2

Release notes

Sourced from picomatch's releases.

2.3.2

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: micromatch/picomatch@2.3.1...2.3.2

Changelog

Sourced from picomatch's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

4.0.0 (2024-02-07)

Fixes

Changed

3.0.1

Fixes

... (truncated)

Commits

Updates @angular-devkit/build-angular from 19.2.16 to 19.2.23

Release notes

Sourced from @​angular-devkit/build-angular's releases.

19.2.23

@​angular/cli

Commit Description
fix - 67cfbe32f update picomatch to 4.0.4

@​angular-devkit/build-angular

Commit Description
fix - 771b979e7 update picomatch to 4.0.4

@​angular-devkit/core

Commit Description
fix - de2da4874 update picomatch to 4.0.4

@​angular/build

Commit Description
fix - 27a9ce4a7 update picomatch to 4.0.4

19.2.22

@​angular-devkit/core

Commit Description
fix - 0a01aecd9 update ajv to 8.18.0

@​angular/build

Commit Description
fix - 79f59412a update rollup to 4.59.0

19.2.21

@​angular/ssr

Commit Description
fix - 288e22816 prevent open redirect via X-Forwarded-Prefix header
fix - 2a72d7483 validate host headers to prevent header-based SSRF

19.2.20

@​angular-devkit/build-angular

Commit Description
fix - 0e5421ba7 update webpack to 5.105.0

19.2.19

@​angular/build

Commit Description
fix - 4d8ea27a1 update vite to v6.4.1

19.2.18

@​angular/ssr

| Commit | Description |

... (truncated)

Changelog

Sourced from @​angular-devkit/build-angular's changelog.

19.2.23 (2026-03-27)

@​angular/cli

Commit Type Description
67cfbe32f fix update picomatch to 4.0.4

@​angular-devkit/build-angular

Commit Type Description
771b979e7 fix update picomatch to 4.0.4

@​angular-devkit/core

Commit Type Description
de2da4874 fix update picomatch to 4.0.4

@​angular/build

Commit Type Description
27a9ce4a7 fix update picomatch to 4.0.4

22.0.0-next.3 (2026-03-26)

@​angular/cli

Commit Type Description
4bbd1bf53 fix restore console methods after logger completes

@​schematics/angular

Commit Type Description
f98cc82eb feat rely on strict template default in generated workspaces

@​angular/build

Commit Type Description
01bd5d064 fix deduplicate and merge coverage excludes with vitest
355ebe8c5 fix prevent reporter duplicates by explicitly overriding Vitest configuration

... (truncated)

Commits
  • 619c0d2 release: cut the v19.2.23 release
  • de2da48 fix(@​angular-devkit/core): update picomatch to 4.0.4
  • 771b979 fix(@​angular-devkit/build-angular): update picomatch to 4.0.4
  • 27a9ce4 fix(@​angular/build): update picomatch to 4.0.4
  • 67cfbe3 fix(@​angular/cli): update picomatch to 4.0.4
  • 3d47bd3 release: cut the v19.2.22 release
  • 0a01aec fix(@​angular-devkit/core): update ajv to 8.18.0
  • 79f5941 fix(@​angular/build): update rollup to 4.59.0
  • 4d9442a release: cut the v19.2.21 release
  • 288e228 fix(@​angular/ssr): prevent open redirect via X-Forwarded-Prefix header
  • Additional commits viewable in compare view

Updates @angular/cli from 19.2.16 to 19.2.23

Release notes

Sourced from @​angular/cli's releases.

19.2.23

@​angular/cli

Commit Description
fix - 67cfbe32f update picomatch to 4.0.4

@​angular-devkit/build-angular

Commit Description
fix - 771b979e7 update picomatch to 4.0.4

@​angular-devkit/core

Commit Description
fix - de2da4874 update picomatch to 4.0.4

@​angular/build

Commit Description
fix - 27a9ce4a7 update picomatch to 4.0.4

19.2.22

@​angular-devkit/core

Commit Description
fix - 0a01aecd9 update ajv to 8.18.0

@​angular/build

Commit Description
fix - 79f59412a update rollup to 4.59.0

19.2.21

@​angular/ssr

Commit Description
fix - 288e22816 prevent open redirect via X-Forwarded-Prefix header
fix - 2a72d7483 validate host headers to prevent header-based SSRF

19.2.20

@​angular-devkit/build-angular

Commit Description
fix - 0e5421ba7 update webpack to 5.105.0

19.2.19

@​angular/build

Commit Description
fix - 4d8ea27a1 update vite to v6.4.1

19.2.18

@​angular/ssr

| Commit | Description |

... (truncated)

Changelog

Sourced from @​angular/cli's changelog.

19.2.23 (2026-03-27)

@​angular/cli

Commit Type Description
67cfbe32f fix update picomatch to 4.0.4

@​angular-devkit/build-angular

Commit Type Description
771b979e7 fix update picomatch to 4.0.4

@​angular-devkit/core

Commit Type Description
de2da4874 fix update picomatch to 4.0.4

@​angular/build

Commit Type Description
27a9ce4a7 fix update picomatch to 4.0.4

22.0.0-next.3 (2026-03-26)

@​angular/cli

Commit Type Description
4bbd1bf53 fix restore console methods after logger completes

@​schematics/angular

Commit Type Description
f98cc82eb feat rely on strict template default in generated workspaces

@​angular/build

Commit Type Description
01bd5d064 fix deduplicate and merge coverage excludes with vitest
355ebe8c5 fix prevent reporter duplicates by explicitly overriding Vitest configuration

... (truncated)

Commits
  • 619c0d2 release: cut the v19.2.23 release
  • de2da48 fix(@​angular-devkit/core): update picomatch to 4.0.4
  • 771b979 fix(@​angular-devkit/build-angular): update picomatch to 4.0.4
  • 27a9ce4 fix(@​angular/build): update picomatch to 4.0.4
  • 67cfbe3 fix(@​angular/cli): update picomatch to 4.0.4
  • 3d47bd3 release: cut the v19.2.22 release
  • 0a01aec fix(@​angular-devkit/core): update ajv to 8.18.0
  • 79f5941 fix(@​angular/build): update rollup to 4.59.0
  • 4d9442a release: cut the v19.2.21 release
  • 288e228 fix(@​angular/ssr): prevent open redirect via X-Forwarded-Prefix header
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [picomatch](https://github.com/micromatch/picomatch) to 2.3.2 and updates ancestor dependencies [picomatch](https://github.com/micromatch/picomatch), [@angular-devkit/build-angular](https://github.com/angular/angular-cli) and [@angular/cli](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Updates `picomatch` from 2.3.1 to 2.3.2
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@2.3.1...2.3.2)

Updates `@angular-devkit/build-angular` from 19.2.16 to 19.2.23
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@19.2.16...v19.2.23)

Updates `@angular/cli` from 19.2.16 to 19.2.23
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@19.2.16...v19.2.23)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 2.3.2
  dependency-type: indirect
- dependency-name: "@angular-devkit/build-angular"
  dependency-version: 19.2.23
  dependency-type: direct:development
- dependency-name: "@angular/cli"
  dependency-version: 19.2.23
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Apr 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants