Skip to content

Bump rollup and @angular-devkit/build-angular#2753

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-49909c7d91
Open

Bump rollup and @angular-devkit/build-angular#2753
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/multi-49909c7d91

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 27, 2026

Bumps rollup to 4.59.0 and updates ancestor dependency @angular-devkit/build-angular. These dependencies need to be updated together.

Updates rollup from 4.34.8 to 4.59.0

Release notes

Sourced from rollup's releases.

v4.59.0

4.59.0

2026-02-22

Features

  • Throw when the generated bundle contains paths that would leave the output directory (#6276)

Pull Requests

v4.58.0

4.58.0

2026-02-20

Features

  • Also support __NO_SIDE_EFFECTS__ annotation before variable declarations declaring function expressions (#6272)

Pull Requests

v4.57.1

4.57.1

2026-01-30

Bug Fixes

  • Fix heap corruption issue in Windows (#6251)
  • Ensure exports of a dynamic import are fully included when called from a try...catch (#6254)

Pull Requests

... (truncated)

Changelog

Sourced from rollup's changelog.

4.59.0

2026-02-22

Features

  • Throw when the generated bundle contains paths that would leave the output directory (#6276)

Pull Requests

4.58.0

2026-02-20

Features

  • Also support __NO_SIDE_EFFECTS__ annotation before variable declarations declaring function expressions (#6272)

Pull Requests

4.57.1

2026-01-30

Bug Fixes

  • Fix heap corruption issue in Windows (#6251)
  • Ensure exports of a dynamic import are fully included when called from a try...catch (#6254)

Pull Requests

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for rollup since your current version.

Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Updates @angular-devkit/build-angular from 19.2.7 to 19.2.22

Release notes

Sourced from @​angular-devkit/build-angular's releases.

19.2.22

@​angular-devkit/core

Commit Description
fix - 0a01aecd9 update ajv to 8.18.0

@​angular/build

Commit Description
fix - 79f59412a update rollup to 4.59.0

19.2.21

@​angular/ssr

Commit Description
fix - 288e22816 prevent open redirect via X-Forwarded-Prefix header
fix - 2a72d7483 validate host headers to prevent header-based SSRF

19.2.20

@​angular-devkit/build-angular

Commit Description
fix - 0e5421ba7 update webpack to 5.105.0

19.2.19

@​angular/build

Commit Description
fix - 4d8ea27a1 update vite to v6.4.1

19.2.18

@​angular/ssr

Commit Description
fix - 9136a5d13 prevent malicious URL from overriding host

19.2.17

@​angular/build

Commit Description
fix - 365d525b5 update vite to 6.3.6

19.2.16

@​angular-devkit/build-angular

Commit Description
fix - b0f4330a9 avoid extra tick in SSR builds

@​angular/build

Commit Description
fix - ee5c5f823 avoid extra tick in SSR dev-server builds

... (truncated)

Changelog

Sourced from @​angular-devkit/build-angular's changelog.

19.2.22 (2026-02-26)

@​angular-devkit/core

Commit Type Description
0a01aecd9 fix update ajv to 8.18.0

@​angular/build

Commit Type Description
79f59412a fix update rollup to 4.59.0

21.2.0 (2026-02-25)

@​angular/cli

Commit Type Description
0dd04f289 feat add markdown files to Prettier's formatting list
fbae1b6ab feat automatic formatting files modified by schematics
91b9d281f feat integrate file formatting into update migrations
98a24d040 feat standardize MCP tools around workspace/project options
d9cd609c5 fix correctly parse scoped packages in yarn classic list output
5b05f2500 fix enable shell option for Prettier execution on Windows platforms
25b8a157d fix quote complex range specifiers in package manager
6f29a8c35 fix renamed files by their new path in the schematic workflow
201a036f2 fix simplify Angular version compatibility checks and add special handling for local builds of new major versions
cdd26bb66 fix validate package manager version using semver.valid and throw an error if invalid
bc363af8b perf optimize package manager discovery with stat-based probing

@​schematics/angular

Commit Type Description
aa7381efd feat add a '.prettierrc' file to generated workspaces and add Prettier as dev dependency
f80db6fb7 feat add ng-add support for Vitest browser providers
5d1df50d8 fix add actionable feedback to vitest-browser schematic

@​angular/build

Commit Type Description
ece30f235 feat add headless option to unit-test builder
cad7a7c0f feat run vitest browser with playwright with OS theme

... (truncated)

Commits
  • 3d47bd3 release: cut the v19.2.22 release
  • 0a01aec fix(@​angular-devkit/core): update ajv to 8.18.0
  • 79f5941 fix(@​angular/build): update rollup to 4.59.0
  • 4d9442a release: cut the v19.2.21 release
  • 288e228 fix(@​angular/ssr): prevent open redirect via X-Forwarded-Prefix header
  • 2a72d74 fix(@​angular/ssr): validate host headers to prevent header-based SSRF
  • 747393c release: cut the v19.2.20 release
  • d37b749 build: update pnpm to 10.15.0
  • 0e5421b fix(@​angular-devkit/build-angular): update webpack to 5.105.0
  • 399c3ec release: cut the v19.2.19 release
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [rollup](https://github.com/rollup/rollup) to 4.59.0 and updates ancestor dependency [@angular-devkit/build-angular](https://github.com/angular/angular-cli). These dependencies need to be updated together.


Updates `rollup` from 4.34.8 to 4.59.0
- [Release notes](https://github.com/rollup/rollup/releases)
- [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md)
- [Commits](rollup/rollup@v4.34.8...v4.59.0)

Updates `@angular-devkit/build-angular` from 19.2.7 to 19.2.22
- [Release notes](https://github.com/angular/angular-cli/releases)
- [Changelog](https://github.com/angular/angular-cli/blob/main/CHANGELOG.md)
- [Commits](angular/angular-cli@19.2.7...v19.2.22)

---
updated-dependencies:
- dependency-name: rollup
  dependency-version: 4.59.0
  dependency-type: indirect
- dependency-name: "@angular-devkit/build-angular"
  dependency-version: 19.2.22
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants