Skip to content

Security: update @angular/platform-server, ws, brace-expansion#33669

Open
aleksei-semikozov wants to merge 2 commits into
DevExpress:26_1from
aleksei-semikozov:security-deps-26_1
Open

Security: update @angular/platform-server, ws, brace-expansion#33669
aleksei-semikozov wants to merge 2 commits into
DevExpress:26_1from
aleksei-semikozov:security-deps-26_1

Conversation

@aleksei-semikozov
Copy link
Copy Markdown
Contributor

No description provided.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates dependency resolutions in the DevExtreme pnpm/Nx monorepo to address security-related package updates (notably Angular platform-server, ws, and brace-expansion) by adjusting the workspace catalog, pnpm overrides, and regenerating the lockfile.

Changes:

  • Bump the angular catalog versions from ~20.3.0 to ~20.3.21 (and related devkit packages).
  • Update pnpm overrides for brace-expansion, @angular/platform-server (21.x range), and ws.
  • Regenerate pnpm-lock.yaml to reflect updated dependency graph and resolutions.

Reviewed changes

Copilot reviewed 2 out of 3 changed files in this pull request and generated 2 comments.

File Description
pnpm-workspace.yaml Updates the shared Angular catalog versions to newer 20.3.x patch levels.
pnpm-lock.yaml Regenerates the lockfile with updated Angular, ws, and brace-expansion resolutions/overrides.
package.json Adjusts pnpm.overrides to force patched dependency versions for security advisories.
Files not reviewed (1)
  • pnpm-lock.yaml: Language not supported

Comment thread package.json
Comment thread pnpm-lock.yaml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants