Skip to content

Bump tar, @angular-devkit/build-angular, @angular/cli and ng-packagr - #150

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-c6ade8959a
Closed

Bump tar, @angular-devkit/build-angular, @angular/cli and ng-packagr#150
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-c6ade8959a

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMar 5, 2026

Copy link
Copy Markdown
Contributor

Bumps tar to 7.5.10 and updates ancestor dependencies tar, @angular-devkit/build-angular, @angular/cli and ng-packagr. These dependencies need to be updated together.

Updates tar from 6.2.1 to 7.5.10

Changelog

Sourced from tar's changelog.

Changelog

7.5

  • Added zstd compression support.
  • Consistent TOCTOU behavior in sync t.list
  • Only read from ustar block if not specified in Pax
  • Fix sync tar.list when file size reduces while reading
  • Sanitize absolute linkpaths properly
  • Prevent writing hardlink entries to the archive ahead of their file target

7.4

  • Deprecate onentry in favor of onReadEntry for clarity.

7.3

  • Add onWriteEntry option

7.2

  • DRY the command definitions into a single makeCommand method, and update the type signatures to more appropriately infer the return type from the options and arguments provided.

7.1

  • Update minipass to v7.1.0
  • Update the type definitions of write() and end() methods on Unpack and Parser classes to be compatible with the NodeJS.WritableStream type in the latest versions of @types/node.

7.0

  • Drop support for node <18
  • Rewrite in TypeScript, provide ESM and CommonJS hybrid interface
  • Add tree-shake friendly exports, like import('tar/create') and import('tar/read-entry') to get individual functions or classes.
  • Add chmod option that defaults to false, and deprecate noChmod. That is, reverse the default option regarding explicitly setting file system modes to match tar entry settings.
  • Add processUmask option to avoid having to call process.umask() when chmod: true (or noChmod: false) is set.

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by isaacs, a new releaser for tar since your current version.

Install script changes

This version adds prepare script that runs during installation. Review the package contents before updating.


Updates @angular-devkit/build-angular from 15.2.11 to 21.2.0

Release notes

Sourced from @​angular-devkit/build-angular's releases.

21.2.0

@​schematics/angular

CommitDescription
feat - aa7381efdadd a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
feat - f80db6fb7add ng-add support for Vitest browser providers
fix - 5d1df50d8add actionable feedback to vitest-browser schematic

@​angular/cli

CommitDescription
feat - 0dd04f289add markdown files to Prettier's formatting list
feat - fbae1b6abautomatic formatting files modified by schematics
feat - 91b9d281fintegrate file formatting into update migrations
feat - 98a24d040standardize MCP tools around workspace/project options
fix - d9cd609c5correctly parse scoped packages in yarn classic list output
fix - 5b05f2500enable shell option for Prettier execution on Windows platforms
fix - 25b8a157dquote complex range specifiers in package manager
fix - 6f29a8c35renamed files by their new path in the schematic workflow
fix - 201a036f2simplify Angular version compatibility checks and add special handling for local builds of new major versions
fix - cdd26bb66validate package manager version using semver.valid and throw an error if invalid
perf - bc363af8boptimize package manager discovery with stat-based probing

@​angular/build

CommitDescription
feat - ece30f235add headless option to unit-test builder
feat - cad7a7c0frun vitest browser with playwright with OS theme
fix - 0b4982720adjust sourcemap sources when Vitest wrapper is bypassed
fix - 1f114a9e8bundle setup files in unit-test builder for Vitest
fix - fd5cb28c8explicitly fail when using Vitest runtime mocking
fix - dc899e8a5normalize allowedHosts in dev-server
fix - 26bbea12fserve extensionless assets without transformation

21.2.0-rc.2

@​angular/cli

CommitDescription
fix - 201a036f2simplify Angular version compatibility checks and add special handling for local builds of new major versions

21.2.0-rc.1

@​angular/cli

CommitDescription
fix - cdd26bb66validate package manager version using semver.valid and throw an error if invalid

@​angular/ssr

CommitDescription
fix - cf5a72d33prevent open redirect via X-Forwarded-Prefix header
fix - f78f38827validate host headers to prevent header-based SSRF

21.2.0-rc.0

... (truncated)

Changelog

Sourced from @​angular-devkit/build-angular's changelog.

21.2.0 (2026-02-25)

@​angular/cli

CommitTypeDescription
0dd04f289featadd markdown files to Prettier's formatting list
fbae1b6abfeatautomatic formatting files modified by schematics
91b9d281ffeatintegrate file formatting into update migrations
98a24d040featstandardize MCP tools around workspace/project options
d9cd609c5fixcorrectly parse scoped packages in yarn classic list output
5b05f2500fixenable shell option for Prettier execution on Windows platforms
25b8a157dfixquote complex range specifiers in package manager
6f29a8c35fixrenamed files by their new path in the schematic workflow
201a036f2fixsimplify Angular version compatibility checks and add special handling for local builds of new major versions
cdd26bb66fixvalidate package manager version using semver.valid and throw an error if invalid
bc363af8bperfoptimize package manager discovery with stat-based probing

@​schematics/angular

CommitTypeDescription
aa7381efdfeatadd a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
f80db6fb7featadd ng-add support for Vitest browser providers
5d1df50d8fixadd actionable feedback to vitest-browser schematic

@​angular/build

CommitTypeDescription
ece30f235featadd headless option to unit-test builder
cad7a7c0ffeatrun vitest browser with playwright with OS theme
0b4982720fixadjust sourcemap sources when Vitest wrapper is bypassed
1f114a9e8fixbundle setup files in unit-test builder for Vitest
fd5cb28c8fixexplicitly fail when using Vitest runtime mocking
dc899e8a5fixnormalize allowedHosts in dev-server
26bbea12ffixserve extensionless assets without transformation

21.1.5 (2026-02-23)

@​angular/ssr

CommitTypeDescription
8695d6063fixprevent open redirect via X-Forwarded-Prefix header
e4d445ec6fixvalidate host headers to prevent header-based SSRF

... (truncated)

Commits
  • 018d493 release: cut the v21.2.0 release
  • 481e40d build: bump framework dependencies to latest minor
  • 54bd6e3 build: lock file maintenance
  • dc899e8 fix(@​angular/build): normalize allowedHosts in dev-server
  • c86193e build: update cross-repo angular dependencies
  • 4041e14 build: update bazel dependencies
  • 26bbea1 fix(@​angular/build): serve extensionless assets without transformation
  • 25b8a15 fix(@​angular/cli): quote complex range specifiers in package manager
  • 42f7d99 docs: clarify CLI debugging example by replacing ellipsis with \<command>
  • 808dab6 release: cut the v21.2.0-rc.2 release
  • Additional commits viewable in compare view

Updates @angular/cli from 15.2.11 to 21.2.0

Release notes

Sourced from @​angular/cli's releases.

21.2.0

@​schematics/angular

CommitDescription
feat - aa7381efdadd a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
feat - f80db6fb7add ng-add support for Vitest browser providers
fix - 5d1df50d8add actionable feedback to vitest-browser schematic

@​angular/cli

CommitDescription
feat - 0dd04f289add markdown files to Prettier's formatting list
feat - fbae1b6abautomatic formatting files modified by schematics
feat - 91b9d281fintegrate file formatting into update migrations
feat - 98a24d040standardize MCP tools around workspace/project options
fix - d9cd609c5correctly parse scoped packages in yarn classic list output
fix - 5b05f2500enable shell option for Prettier execution on Windows platforms
fix - 25b8a157dquote complex range specifiers in package manager
fix - 6f29a8c35renamed files by their new path in the schematic workflow
fix - 201a036f2simplify Angular version compatibility checks and add special handling for local builds of new major versions
fix - cdd26bb66validate package manager version using semver.valid and throw an error if invalid
perf - bc363af8boptimize package manager discovery with stat-based probing

@​angular/build

CommitDescription
feat - ece30f235add headless option to unit-test builder
feat - cad7a7c0frun vitest browser with playwright with OS theme
fix - 0b4982720adjust sourcemap sources when Vitest wrapper is bypassed
fix - 1f114a9e8bundle setup files in unit-test builder for Vitest
fix - fd5cb28c8explicitly fail when using Vitest runtime mocking
fix - dc899e8a5normalize allowedHosts in dev-server
fix - 26bbea12fserve extensionless assets without transformation

21.2.0-rc.2

@​angular/cli

CommitDescription
fix - 201a036f2simplify Angular version compatibility checks and add special handling for local builds of new major versions

21.2.0-rc.1

@​angular/cli

CommitDescription
fix - cdd26bb66validate package manager version using semver.valid and throw an error if invalid

@​angular/ssr

CommitDescription
fix - cf5a72d33prevent open redirect via X-Forwarded-Prefix header
fix - f78f38827validate host headers to prevent header-based SSRF

21.2.0-rc.0

... (truncated)

Changelog

Sourced from @​angular/cli's changelog.

21.2.0 (2026-02-25)

@​angular/cli

CommitTypeDescription
0dd04f289featadd markdown files to Prettier's formatting list
fbae1b6abfeatautomatic formatting files modified by schematics
91b9d281ffeatintegrate file formatting into update migrations
98a24d040featstandardize MCP tools around workspace/project options
d9cd609c5fixcorrectly parse scoped packages in yarn classic list output
5b05f2500fixenable shell option for Prettier execution on Windows platforms
25b8a157dfixquote complex range specifiers in package manager
6f29a8c35fixrenamed files by their new path in the schematic workflow
201a036f2fixsimplify Angular version compatibility checks and add special handling for local builds of new major versions
cdd26bb66fixvalidate package manager version using semver.valid and throw an error if invalid
bc363af8bperfoptimize package manager discovery with stat-based probing

@​schematics/angular

CommitTypeDescription
aa7381efdfeatadd a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
f80db6fb7featadd ng-add support for Vitest browser providers
5d1df50d8fixadd actionable feedback to vitest-browser schematic

@​angular/build

CommitTypeDescription
ece30f235featadd headless option to unit-test builder
cad7a7c0ffeatrun vitest browser with playwright with OS theme
0b4982720fixadjust sourcemap sources when Vitest wrapper is bypassed
1f114a9e8fixbundle setup files in unit-test builder for Vitest
fd5cb28c8fixexplicitly fail when using Vitest runtime mocking
dc899e8a5fixnormalize allowedHosts in dev-server
26bbea12ffixserve extensionless assets without transformation

21.1.5 (2026-02-23)

@​angular/ssr

CommitTypeDescription
8695d6063fixprevent open redirect via X-Forwarded-Prefix header
e4d445ec6fixvalidate host headers to prevent header-based SSRF

... (truncated)

Commits
  • 018d493 release: cut the v21.2.0 release
  • 481e40d build: bump framework dependencies to latest minor
  • 54bd6e3 build: lock file maintenance
  • dc899e8 fix(@​angular/build): normalize allowedHosts in dev-server
  • c86193e build: update cross-repo angular dependencies
  • 4041e14 build: update bazel dependencies
  • 26bbea1 fix(@​angular/build): serve extensionless assets without transformation
  • 25b8a15 fix(@​angular/cli): quote complex range specifiers in package manager
  • 42f7d99 docs: clarify CLI debugging example by replacing ellipsis with \<command>
  • 808dab6 release: cut the v21.2.0-rc.2 release
  • Additional commits viewable in compare view

Updates ng-packagr from 15.2.2 to 21.2.0

Release notes

Sourced from ng-packagr's releases.

21.2.0

No public facing changes.

21.2.0-next.0

No release notes provided.

21.1.0

Features

  • add importAttributesKey: 'with' to Rollup output options (ba4f690), closes #3212

Bug Fixes

  • correctly identify external modules (7c24c84)

21.1.0-rc.0

Features

  • add importAttributesKey: 'with' to Rollup output options (ba4f690), closes #3212

21.0.1

Bug Fixes

  • correctly identify external modules (e0f7b22)

21.0.0

⚠ BREAKING CHANGES

  • TypeScript versions older than 5.9 are no longer supported.
  • The javascriptEnabled option for Less is no longer supported. Projects relying on inline JavaScript within Less files will need to refactor their stylesheets to remove this dependency.

Bug Fixes

  • drop support for TypeScript 5.8 (7b48224)
  • remove deprecated javascriptEnabled option for Less (d57278d)

Features

  • write the types in types directory (7a5e8fb)
  • add support for Angular version 21 (ed70e23)

21.0.0-rc.1

Performance

  • reduce memory usage for multiple entry-points (non-watch) (01bdd42), closes #3168

... (truncated)

Changelog

Sourced from ng-packagr's changelog.

Changelog

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

22.0.0-next.0 (2026-02-25)

⚠ BREAKING CHANGES

  • Node.js v20 is no longer supported. The minimum supported Node.js versions are now v22.22.0 and v24.13.1.

Features

  • update @​angular/compiler-cli peer dependency to support Angular v22 (1fd8eb1)

Bug Fixes

  • allow TypeScript 6 peer dependency (fdb49da)

  • update minimum supported Node.js versions (f7e5ef5)

21.2.0-next.0 (2026-01-14)

21.1.0 (2026-01-14)

Features

  • add importAttributesKey: 'with' to Rollup output options (ba4f690), closes #3212

Bug Fixes

  • correctly identify external modules (7c24c84)

21.0.1 (2025-12-15)

Bug Fixes

  • correctly identify external modules (e0f7b22)

21.1.0-next.0 (2025-11-19)

21.1.0-next.0 (2025-11-19)

21.0.0 (2025-11-19)

⚠ BREAKING CHANGES

... (truncated)

Commits
  • 4d7fa2d release: cut 21.2.0
  • 30e7b0e build: broaden @angular/compiler-cli peer dependency
  • 37e545f build: update all non-major dependencies to v8.55.0
  • 0d3d910 build: lock file maintenance
  • 7235db9 build: update actions/checkout action to v6.0.2
  • 2c4c682 build: lock file maintenance
  • 1528834 build: update pnpm to v10.28.2
  • 3fb021c build: update all non-major dependencies to v8.54.0
  • 8876131 build: update cross-repo angular dependencies to ~21.2.0-next
  • 3cca2d9 build: lock file maintenance
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for ng-packagr since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [tar](https://github.com/isaacs/node-tar) to 7.5.10 and updates ancestor dependencies [tar](https://github.com/isaacs/node-tar), [@angular-devkit/build-angular](https://github.com/angular/angular-cli), [@angular/cli](https://github.com/angular/angular-cli) and [ng-packagr](https://github.com/ng-packagr/ng-packagr). These dependencies need to be updated together.
Updates `tar` from 6.2.1 to 7.5.10
- [Release notes](https://github.com/isaacs/node-tar/releases)
- [Changelog](https://github.com/isaacs/node-tar/blob/main/CHANGELOG.md)
- [Commits](isaacs/node-tar@v6.2.1...v7.5.10)
Updates `@angular-devkit/build-angular` from 15.2.11 to 21.2.0
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@15.2.11...v21.2.0)
Updates `@angular/cli` from 15.2.11 to 21.2.0
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@15.2.11...v21.2.0)
Updates `ng-packagr` from 15.2.2 to 21.2.0
- [Release notes](https://github.com/ng-packagr/ng-packagr/releases)
- [Changelog](https://github.com/ng-packagr/ng-packagr/blob/main/CHANGELOG.md)
- [Commits](ng-packagr/ng-packagr@15.2.2...21.2.0)
---
updated-dependencies:
- dependency-name: tar
dependency-version: 7.5.10
dependency-type: indirect
- dependency-name: "@angular-devkit/build-angular"
dependency-version: 21.2.0
dependency-type: direct:development
- dependency-name: "@angular/cli"
dependency-version: 21.2.0
dependency-type: direct:development
- dependency-name: ng-packagr
dependency-version: 21.2.0
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 5, 2026
@dependabot@github

dependabotBot commented on behalf of githubMar 10, 2026

Copy link
Copy Markdown
ContributorAuthor

Superseded by #154.

@dependabotdependabotBot closed this Mar 10, 2026
@dependabot
dependabotBot deleted the dependabot/npm_and_yarn/multi-c6ade8959a branch March 10, 2026 23:50
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants