Sitelet https://github.com/angular/angular/compare/v20.3.27...v20.3.28
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: angular/angular
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v20.3.27
Choose a base ref
...
head repository: angular/angular
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v20.3.28
Choose a head ref
  • 5 commits
  • 29 files changed
  • 2 contributors

Commits on Jul 30, 2026

  1. fix(core): sanitize host bindings on concrete hosts

    Compute host binding security contexts against concrete hosts, including host directives, inheritance, dynamic directives, and createComponent hostElement usage.
    SkyZeroZx authored Jul 30, 2026
    Configuration menu
    Copy the full SHA
    2f96c80 View commit details
    Browse the repository at this point in the history

Commits on Jul 31, 2026

  1. fix(http): preserve immutability of materialized clones

    Prevent lazy HttpHeaders and HttpParams clones from reusing value arrays owned by a materialized source. Append and value-specific delete operations previously mutated those shared arrays, violating the immutable API contract and allowing request metadata to bleed into later requests.
    
    Share value arrays until an update mutates a specific header or parameter, then copy only that array. Cover the affected append and delete paths with regression tests that materialize the source first.
    SkyZeroZx authored and thePunderWoman committed Jul 31, 2026
    Configuration menu
    Copy the full SHA
    29dd26b View commit details
    Browse the repository at this point in the history
  2. fix(http): match header values exactly when deleting

    Normalize value-specific HttpHeaders deletions before filtering. The string overload previously used String#indexOf and removed shorter values contained within the requested deletion value, potentially widening outgoing request metadata.
    
    Preserve delete-all behavior only when no value is supplied, and cover string, array, and empty-string deletion.
    SkyZeroZx authored and thePunderWoman committed Jul 31, 2026
    Configuration menu
    Copy the full SHA
    969133d View commit details
    Browse the repository at this point in the history
  3. fix(http): run root interceptors in the terminal request chain

    Represent withRequestsMadeViaParent() with an internal delegating backend so the interceptor handler can distinguish delegated clients from independent child configurations.
    SkyZeroZx authored and thePunderWoman committed Jul 31, 2026
    Configuration menu
    Copy the full SHA
    e4c416c View commit details
    Browse the repository at this point in the history

Commits on Aug 13, 2026

  1. Configuration menu
    Copy the full SHA
    1d576ee View commit details
    Browse the repository at this point in the history
Loading