Skip to content

fix(@angular/build): bump piscina to 5.3.2 - #34244

Merged
alan-agius4 merged 1 commit into
angular:20.3.xfrom
alan-agius4:fix/piscina-20.3.x
Oct 2, 2026
Merged

alan-agius4 merged 1 commit into
angular:20.3.xfrom
alan-agius4:fix/piscina-20.3.x

Conversation

@alan-agius4

Copy link
Copy Markdown
Collaborator

Bumps piscina to 5.3.2 to address GHSA-67c8-pqhq-4rmx / CVE-2026-102992.

Closes #34241

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the 'piscina' dependency from version 5.2.0 to 5.3.2 in both 'packages/angular/build/package.json' and 'packages/angular_devkit/build_angular/package.json'. There are no review comments, and I have no feedback to provide.

@alan-agius4
alan-agius4 requested a review from dgp1130 October 2, 2026 08:47
@alan-agius4 alan-agius4 added action: review The PR is still awaiting reviews from at least one requested reviewer target: lts This PR is targeting a version currently in long-term support labels Oct 2, 2026
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Oct 2, 2026
@alan-agius4
alan-agius4 merged commit 3e39e33 into angular:20.3.x Oct 2, 2026
34 of 35 checks passed
@alan-agius4

Copy link
Copy Markdown
Collaborator Author

This PR was merged into the repository. The changes were merged into the following branches:

@alan-agius4
alan-agius4 deleted the fix/piscina-20.3.x branch October 2, 2026 18:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: @angular/build target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

@angular/build@^21 depends on piscina@5.2.0 which is vulnerable to CVE-2026-102992

2 participants