Skip to content

Bump node-forge and @angular-devkit/build-angular in /pingone-angular-openidconnect-sample - #30

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/pingone-angular-openidconnect-sample/multi-0b306eb139
Open

Bump node-forge and @angular-devkit/build-angular in /pingone-angular-openidconnect-sample#30
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/pingone-angular-openidconnect-sample/multi-0b306eb139

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMar 28, 2026

Copy link
Copy Markdown
Contributor

Removes node-forge. It's no longer used after updating ancestor dependency @angular-devkit/build-angular. These dependencies need to be updated together.

Removes node-forge

Updates @angular-devkit/build-angular from 0.901.0 to 21.2.5

Release notes

Sourced from @​angular-devkit/build-angular's releases.

21.2.5

@​angular/cli

CommitDescription
feat - cadf9b201support custom port in MCP devserver start tool

@​angular/ssr

CommitDescription
fix - bbc255419allow underscores in host validation
fix - b1fe66a7fpatch Headers.forEach in cloneRequestAndPatchHeaders

21.2.4

@​angular/cli

CommitDescription
fix - a7787d092restore console methods after logger completes

@​angular/build

CommitDescription
fix - 7170599abdeduplicate and merge coverage excludes with vitest
fix - c73f13797prevent reporter duplicates by explicitly overriding Vitest configuration
fix - 956ccaa71remove default for unit-test coverage option
fix - 36978db7ewarn about performance of test.exclude in vitest configuration
fix - 6ec36f5bewarn when vitest watch config conflicts with builder

@​angular/ssr

CommitDescription
fix - 9bdf782c8apply forwarded prefix and vary header in accept-language redirects
fix - 628c58672support '*' in allowedHosts and warn about security risks

21.2.3

@​angular/cli

CommitDescription
fix - 1505164bbuse parsed package name for migrate-only updates

@​angular/build

CommitDescription
fix - 75fa94cadalias createRequire banner import to avoid duplicate binding
fix - d009aa1econly use external packages for polyfills when no local files are present

@​angular/ssr

CommitDescription
fix - f3e0e82c2disallow x-forwarded-prefix starting with a backslash
fix - b8bcd59b4ensure unique values in redirect response Vary header
fix - 84385411dsupport custom headers in redirect responses

21.2.2

@​angular/cli

| Commit | Description |

... (truncated)

Changelog

Sourced from @​angular-devkit/build-angular's changelog.

21.2.5 (2026-03-27)

@​angular/cli

CommitTypeDescription
cadf9b201featsupport custom port in MCP devserver start tool

@​angular/ssr

CommitTypeDescription
bbc255419fixallow underscores in host validation
b1fe66a7ffixpatch Headers.forEach in cloneRequestAndPatchHeaders

20.3.22 (2026-03-27)

@​angular-devkit/build-angular

CommitTypeDescription
5978eeefffixupdate picomatch to 4.0.4

@​angular-devkit/core

CommitTypeDescription
6e9b92612fixupdate picomatch to 4.0.4

@​angular/build

CommitTypeDescription
6f209c26dfixupdate picomatch to 4.0.4

19.2.23 (2026-03-27)

@​angular/cli

CommitTypeDescription
67cfbe32ffixupdate picomatch to 4.0.4

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by google-wombot, a new releaser for @​angular-devkit/build-angular since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Removes [node-forge](https://github.com/digitalbazaar/forge). It's no longer used after updating ancestor dependency [@angular-devkit/build-angular](https://github.com/angular/angular-cli). These dependencies need to be updated together.
Removes `node-forge`
Updates `@angular-devkit/build-angular` from 0.901.0 to 21.2.5
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular-cli/commits/v21.2.5)
---
updated-dependencies:
- dependency-name: node-forge
dependency-version: dependency-type: indirect
- dependency-name: "@angular-devkit/build-angular"
dependency-version: 21.2.5
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 28, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants