Skip to content

Bump minimatch, cordova-browser and @angular-devkit/build-angular#46

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-bf55379ede
Open

Bump minimatch, cordova-browser and @angular-devkit/build-angular#46
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-bf55379ede

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 27, 2026

Copy link
Copy Markdown

Bumps minimatch to 3.1.5 and updates ancestor dependencies minimatch, cordova-browser and @angular-devkit/build-angular. These dependencies need to be updated together.

Updates minimatch from 3.0.4 to 3.1.5

Commits

Updates cordova-browser from 5.0.4 to 7.0.0

Changelog

Sourced from cordova-browser's changelog.

7.0.0 (May 13, 2023)

Breaking Changes

  • GH-121 Minimum NodeJS Required: 16.13.0
  • GH-115 Update ShellJS to 0.8.5.
  • GH-78 feat: Replace Q with native Promises.

Other Notable Changes

  • GH-117 Added .npmrc file to ensure the official NPM registry is used during development and deployments.
  • GH-107 Enabled package-lock.json file.
  • GH-119 Added NodeJS 20 to our test matrix.
  • GH-118 Updated ESLint config to match better match Apache Cordova's coding style standards.
  • GH-80 Enabled CodeCov test coverage
  • GH-113 Migrated to GitHub Action workflows for our testing CI.

For a full list of changes, see the commit history

6.0.0 (Feb 01, 2019)

  • GH-70 Browser Platform Release Preparation (Cordova 9)
  • GH-68 Copy node_modules if the directory exists
  • GH-63 Dependency bump cordova-common@^3.0.0
  • CB-13740 Return expected promise resolving with array
  • GH-59 Remove Bundled Dependencies
  • CB-14073 Browser: Drop Node 4, Added Node 10
  • CB-14252 Allow to send --silent arg to run command to disable output (#57)
  • CB-13999 (browser) - Reading config.xml respects base href (#52)
  • GH-50 corrected path for config.xml
  • CB-13689 Updated RELEASENOTES and Version for release 5.0.3

5.0.2 (Dec 18, 2017)

  • CB-13689: Updated checked-in node_modules
  • CB-13562: fixed asset tag when adding push plugin to Browser

5.0.1 (Oct 16, 2017)

  • CB-13444 Updated checked-in node_modules
  • CB-13435 fix merges directory support for Browser
  • CB-12895 ignoring cordova.js for eslint

5.0.0 (Aug 24, 2017)

  • CB-13214 Updated cordova-serve dependnecy to 2.0.0. cordova serve command now opens system default browser instead of a new instance of chrome. A specific target can still be passed in.
  • CB-13214 Updated checked-in node_modules
  • CB-13188 fixed issues with run and build scripts.
  • CB-12895: set up eslint and remove jshint
  • CB-11181 add default favicon
  • CB-11710 Add missing 'clean.bat' file
  • remove old xhr-activex Windows code, update to use pagevisibility instead of webkitpagevisibility
  • CB-12804: manifest.json added to Browser during create. Adding basic PWA support
  • CB-12762 Point repo items to github mirrors

... (truncated)

Commits
  • be3084d Curated 7.0.0 release notes
  • 4669c4d Set VERSION to 7.0.0 (via coho)
  • 29469f5 Update JS snapshot to version 7.0.0 (via coho)
  • f45ac8f dep!: bump all possible dependencies w/ node engine >=16.13.0 requirement (#121)
  • d9ded1c chore!: set node engine to >=16.0.0 (#120)
  • 492714a ci: Add NodeJS 20 to matrix. Dropped NodeJS 14. (#119)
  • 529aba2 refactor: @​cordova/eslint-config@^5.0.0 upgrade (#118)
  • 3966de3 chore: Added .npmrc (#117)
  • 4fe7e97 fix: update shelljs to 0.8.5 (#115)
  • 2218451 chore!: drop node 10 and node 12 support (#114)
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by normanbreau, a new releaser for cordova-browser since your current version.


Updates @angular-devkit/build-angular from 0.801.3 to 21.2.0

Release notes

Sourced from @​angular-devkit/build-angular's releases.

21.2.0

@​schematics/angular

Commit Description
feat - aa7381efd add a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
feat - f80db6fb7 add ng-add support for Vitest browser providers
fix - 5d1df50d8 add actionable feedback to vitest-browser schematic

@​angular/cli

Commit Description
feat - 0dd04f289 add markdown files to Prettier's formatting list
feat - fbae1b6ab automatic formatting files modified by schematics
feat - 91b9d281f integrate file formatting into update migrations
feat - 98a24d040 standardize MCP tools around workspace/project options
fix - d9cd609c5 correctly parse scoped packages in yarn classic list output
fix - 5b05f2500 enable shell option for Prettier execution on Windows platforms
fix - 25b8a157d quote complex range specifiers in package manager
fix - 6f29a8c35 renamed files by their new path in the schematic workflow
fix - 201a036f2 simplify Angular version compatibility checks and add special handling for local builds of new major versions
fix - cdd26bb66 validate package manager version using semver.valid and throw an error if invalid
perf - bc363af8b optimize package manager discovery with stat-based probing

@​angular/build

Commit Description
feat - ece30f235 add headless option to unit-test builder
feat - cad7a7c0f run vitest browser with playwright with OS theme
fix - 0b4982720 adjust sourcemap sources when Vitest wrapper is bypassed
fix - 1f114a9e8 bundle setup files in unit-test builder for Vitest
fix - fd5cb28c8 explicitly fail when using Vitest runtime mocking
fix - dc899e8a5 normalize allowedHosts in dev-server
fix - 26bbea12f serve extensionless assets without transformation

21.2.0-rc.2

@​angular/cli

Commit Description
fix - 201a036f2 simplify Angular version compatibility checks and add special handling for local builds of new major versions

21.2.0-rc.1

@​angular/cli

Commit Description
fix - cdd26bb66 validate package manager version using semver.valid and throw an error if invalid

@​angular/ssr

Commit Description
fix - cf5a72d33 prevent open redirect via X-Forwarded-Prefix header
fix - f78f38827 validate host headers to prevent header-based SSRF

21.2.0-rc.0

... (truncated)

Changelog

Sourced from @​angular-devkit/build-angular's changelog.

21.2.0 (2026-02-25)

@​angular/cli

Commit Type Description
0dd04f289 feat add markdown files to Prettier's formatting list
fbae1b6ab feat automatic formatting files modified by schematics
91b9d281f feat integrate file formatting into update migrations
98a24d040 feat standardize MCP tools around workspace/project options
d9cd609c5 fix correctly parse scoped packages in yarn classic list output
5b05f2500 fix enable shell option for Prettier execution on Windows platforms
25b8a157d fix quote complex range specifiers in package manager
6f29a8c35 fix renamed files by their new path in the schematic workflow
201a036f2 fix simplify Angular version compatibility checks and add special handling for local builds of new major versions
cdd26bb66 fix validate package manager version using semver.valid and throw an error if invalid
bc363af8b perf optimize package manager discovery with stat-based probing

@​schematics/angular

Commit Type Description
aa7381efd feat add a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
f80db6fb7 feat add ng-add support for Vitest browser providers
5d1df50d8 fix add actionable feedback to vitest-browser schematic

@​angular/build

Commit Type Description
ece30f235 feat add headless option to unit-test builder
cad7a7c0f feat run vitest browser with playwright with OS theme
0b4982720 fix adjust sourcemap sources when Vitest wrapper is bypassed
1f114a9e8 fix bundle setup files in unit-test builder for Vitest
fd5cb28c8 fix explicitly fail when using Vitest runtime mocking
dc899e8a5 fix normalize allowedHosts in dev-server
26bbea12f fix serve extensionless assets without transformation

21.1.5 (2026-02-23)

@​angular/ssr

Commit Type Description
8695d6063 fix prevent open redirect via X-Forwarded-Prefix header
e4d445ec6 fix validate host headers to prevent header-based SSRF

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by google-wombot, a new releaser for @​angular-devkit/build-angular since your current version.


Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [minimatch](https://github.com/isaacs/minimatch) to 3.1.5 and updates ancestor dependencies [minimatch](https://github.com/isaacs/minimatch), [cordova-browser](https://github.com/apache/cordova-browser) and [@angular-devkit/build-angular](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Updates `minimatch` from 3.0.4 to 3.1.5
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v3.0.4...v3.1.5)

Updates `cordova-browser` from 5.0.4 to 7.0.0
- [Changelog](https://github.com/apache/cordova-browser/blob/master/RELEASENOTES.md)
- [Commits](apache/cordova-browser@5.0.4...7.0.0)

Updates `@angular-devkit/build-angular` from 0.801.3 to 21.2.0
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](https://github.com/angular/angular-cli/commits/v21.2.0)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 3.1.5
  dependency-type: indirect
- dependency-name: cordova-browser
  dependency-version: 7.0.0
  dependency-type: direct:production
- dependency-name: "@angular-devkit/build-angular"
  dependency-version: 21.2.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants