[Snyk] Upgrade @angular/router from 21.2.17 to 22.0.0#86
Open
shafeeqd959 wants to merge 1 commit into
Open
Conversation
Snyk has created this PR to upgrade @angular/router from 21.2.17 to 22.0.0. See this package in npm: @angular/router See this project in Snyk: https://app.snyk.io/org/contentstack-devex/project/11c47692-61cb-4ece-ba33-ab2c35193373?utm_source=github&utm_medium=referral&page=upgrade-pr
🔒 Security Scan Results
⏱️ SLA Breach Summary
ℹ️ Vulnerabilities Without Available Fixes (Informational Only)The following vulnerabilities were detected but do not have fixes available (no upgrade or patch). These are excluded from failure thresholds:
✅ BUILD PASSED - All security checks passed |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade @angular/router from 21.2.17 to 22.0.0.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
The recommended version is 18 versions ahead of your current version.
The recommended version was released 22 days ago.
Release notes
Package name: @angular/router
-
22.0.0 - 2026-06-03
- fix(language-service): Add support for
- feat(language-service): add Document Symbols support for Angular templates (cfd0f9950c)
- feat(language-service): add angular template inlay hints support (5a6d88626b)
- feat(language-service): Add support for idle timeout in defer blocks (c6f98c723c)
-
22.0.0-rc.3 - 2026-06-01
Commit
Description

only strip a literal /index.html suffix from URLs
Commit
Description

move projection attributes into constants
Commit
Description

use Object.create(null) for LOCALE_DATA as a hardening measure
Commit
Description

Make the safe optional chaining idempotent
Commit
Description

throw on suspicious URLs and restrict protocol-relative URLs
-
22.0.0-rc.2 - 2026-05-28
Commit
Description

add upper bounds for digitsInfo

sanitize placeholder
Commit
Description

normalize tag names with custom namespaces in DomElementSchemaRegistry (#68868)

prevent namespaced SVG <style> elements from being stripped

sanitize dynamic href and xlink:href bindings on SVG a elements (#68868)
Commit
Description

do not register dom triggers when defer blocks are in manual mode

normalize tag names in runtime i18n attribute security context lookup (#68868)

prevent rxResource from leaking a subscription

sanitize meta selectors
Commit
Description

avoid redundant invalidations in parser errors signal
Commit
Description

exclude withCredentials requests from transfer cache

Introduce a max buffer size for fetch requests on SSR

prevent

skip TransferCache for cookie-bearing requests by default
Commit
Description

prevent SSRF bypasses via backslash URLs in HttpClient

secure location and document initialization against SSRF and path hijack
Commit
Description

Preserves explicit 'credentials: omit' in asset requests

Preserves HTTP cache mode in asset group requests
-
22.0.0-rc.1 - 2026-05-20
-
22.0.0-rc.0 - 2026-05-13
-
22.0.0-next.12 - 2026-05-08
-
22.0.0-next.11 - 2026-05-06
-
22.0.0-next.10 - 2026-04-29
-
22.0.0-next.9 - 2026-04-22
-
22.0.0-next.8 - 2026-04-15
-
22.0.0-next.7 - 2026-04-08
-
22.0.0-next.6 - 2026-04-01
-
22.0.0-next.5 - 2026-03-25
-
22.0.0-next.4 - 2026-03-19
-
22.0.0-next.3 - 2026-03-12
-
22.0.0-next.2 - 2026-03-11
-
22.0.0-next.1 - 2026-03-05
-
22.0.0-next.0 - 2026-03-04
-
21.2.17 - 2026-06-10
from @angular/router GitHub release notesBreaking Changes
The extension now bundles TypeScript version 6.0, which itself includes breaking
changes, including new defaults such as
strictbeingtrue. You will need to explicitly set"strict": falsein yourtsconfig.json. Alternatively, the extension supports configuring thetsdkin the same way as the built in TS/JS extension.Fixes and features
@ Inputwith transforms (dc9c72da9b)common
compiler
core
migrations
platform-server
common
compiler
core
forms
http
httpResourcefrom leaking a subscriptionplatform-server
service-worker
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: