Sitelet https://github.com/angular/angular/compare/angular:a075161...angular:4d62760
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: angular/angular
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: a075161
Choose a base ref
...
head repository: angular/angular
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 4d62760
Choose a head ref
  • 7 commits
  • 24 files changed
  • 3 contributors

Commits on Jun 24, 2026

  1. fix(core): avoid caching missing locale data

    Only cache locale data loaded from the global locale registry when an actual locale entry is found.
    
    This prevents attacker-controlled missing locale identifiers from being retained indefinitely in SSR when locale lookup falls back to a parent locale or the built-in English locale, avoiding unbounded process memory growth in locale-aware pipes and formatters.
    
    (cherry picked from commit ea8277a)
    SkyZeroZx authored and kirjs committed Jun 24, 2026
    Configuration menu
    Copy the full SHA
    26831d0 View commit details
    Browse the repository at this point in the history

Commits on Jul 1, 2026

  1. fix(core): reject dynamic script host elements

    The previous fix for GHSA-692r-grfm-v8x7 was incomplete because it rejected script tags only when locating an explicit host element. Dynamic component instantiation can also infer the host element from the component selector.
    
    Move the script-host rejection to the point where ComponentFactory has resolved the host element for either path, so createComponent rejects script hosts consistently.
    
    (cherry picked from commit 135f375)
    SkyZeroZx authored and alxhub committed Jul 1, 2026
    Configuration menu
    Copy the full SHA
    8eb7aea View commit details
    Browse the repository at this point in the history

Commits on Jul 6, 2026

  1. fix(compiler-cli): update babel dependencies to latest v7

    Update babel dependencies to v7.29.7 to address CVE-2026-49356.
    
    Fixes #69608
    alan-agius4 authored and leonsenft committed Jul 6, 2026
    Configuration menu
    Copy the full SHA
    406aaa3 View commit details
    Browse the repository at this point in the history

Commits on Jul 7, 2026

  1. fix(http): prevent caching of responses with Set-Cookie headers

    Skip HttpTransferCache serialization for HTTP responses that contain a
    Set-Cookie header.
    
    Cookie-setting responses commonly represent session-specific,
    user-specific, or security-sensitive state. Serializing their bodies into
    SSR TransferState can embed sensitive data into the generated HTML, where
    it may be reused during hydration or replayed by a shared cache/CDN.
    
    (cherry picked from commit 80795de)
    SkyZeroZx authored and leonsenft committed Jul 7, 2026
    Configuration menu
    Copy the full SHA
    b963f61 View commit details
    Browse the repository at this point in the history

Commits on Jul 8, 2026

  1. fix(service-worker): preserve referrer in asset requests

    Preserve referrer metadata when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.
    
    For example, an attacker with access to asset host logs could receive a reset token embedded in a page URL if the reconstructed request falls back to default referrer behavior instead of carrying referrer: ''.
    
    (cherry picked from commit 99ad47e)
    SkyZeroZx authored and leonsenft committed Jul 8, 2026
    Configuration menu
    Copy the full SHA
    1fdf234 View commit details
    Browse the repository at this point in the history
  2. fix(service-worker): preserve referrer policy in asset requests

    Preserve explicit referrer policy when the service worker reconstructs asset requests for cache-busted and redirected asset fetches.
    
    For example, an application can load a script or image with referrerPolicy: 'same-origin' or 'origin' to limit referrer data. Dropping that policy can expose more of the current URL to that resource host.
    
    (cherry picked from commit a7f52e5)
    SkyZeroZx authored and leonsenft committed Jul 8, 2026
    Configuration menu
    Copy the full SHA
    baa093b View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    4d62760 View commit details
    Browse the repository at this point in the history
Loading