38441 Commits

Author SHA1 Message Date
Kam e0593ecc8b refactor(compiler-cli): drop @ts-ignore around fs.readFileSync
The `readFileBuffer` method in `node_js_file_system.ts` was wrapped in
`@ts-ignore` to suppress a TS2322 Buffer/Uint8Array typing error that
was fixed in the TypeScript 5.9.2 upgrade. The minimum supported
TypeScript is now 6.0, so the suppression is dead.
2026-05-12 13:21:53 -07:00
Joey Perrott cdef73a249 build: update @angular/ng-dev
Update the @angular/ng-dev dependency to the latest build to pull in recent fixes and improvements.
2026-05-12 12:08:55 -07:00
Angular Robot 66b9259401 build: lock file maintenance
See associated pull request for more information.
2026-05-12 11:42:31 -07:00
Aleksander Bodurri 84d757446b refactor(devtools): use WeakRef in idToInjector map for injector cleanup
Replace the manual injectorsSeen cleanup mechanism with WeakRef and FinalizationRegistry. The old approach worked but coupled cleanup to the UI change detection and required tracking seen injectors across traversal. WeakRef lets the browser handle this naturally, removing the injectorsSeen set and the manual cleanup loop.
2026-05-12 11:37:07 -07:00
SkyZeroZx a617967d90 refactor(http): update HTTP resource options APIs to stable
Marks `HttpResourceRequest`, `HttpResourceOptions`, and `HttpResourceRef` as public APIs following the stabilization of the Resource API in https://github.com/angular/angular/pull/68253
2026-05-12 10:48:03 -07:00
Paul Gschwendtner 95034a7b92 ci: mark devversion as unavailable
Currently OOO and I don't want reviews to be necessarily stuck for too long.
2026-05-12 10:47:09 -07:00
Alan Agius e90423f5f7 build: disable strict release age checks in pnpm workspaces
Updates all pnpm-workspace.yaml configurations across the repository to set minimumReleaseAgeStrict: false. This resolves dependency installation failures caused by missing time field metadata in the npm registry for certain packages such as @babel/helper-globals. A TODO comment is also added to each configuration file to track future investigation of this registry metadata issue.
2026-05-12 10:43:00 -07:00
Matthew Beck 62710ad4d6 docs: release notes for the v20.3.21 release 2026-05-12 10:13:01 -07:00
Alan Agius 62f8dbb626 build: remove @angular-devkit/build-angular dependency and configure pnpm resolution mode
Try to fix pnpm 11 and defer integration test.
2026-05-12 08:49:44 -07:00
Angular Robot 7acac39ada build: update pnpm to v11.1.0
See associated pull request for more information.

Closes #68687 as a pr takeover
2026-05-12 08:49:44 -07:00
Andrew Scott 1f287b9ba7 refactor(router): Move target RouterState creation before 'blocking' stage
This change moves `RouterState` creation to _before_ the `afterPreactivation` step,
which is the step that pauses until bootstrap listeners are complete. It is used for
'enabled blocking' initial navigation and destructive hydration. After this stage,
activation is expected to be (more or less) synchronous.

More importantly than above (since enabled blocking and destructive hydration are
essentially deprecated), this also oves the state creation before the view transition
creation.

These are done to accomodate features in the future that would depend on the RouterState
(e.g. ones which need to know which `ActivatedRoute` instances are new and which are reused).
These features may include additional async blocks/waits, which should not happen after view
transition creation (which freezes the UI until resolved).
2026-05-11 18:29:52 -07:00
Kam e661f4d255 refactor(compiler-cli): replace forEach with for...of in entry_point
Convert four `.forEach()` calls in `private_export_checker.ts` and
`reference_graph.ts` to `for...of`, matching the iteration style used
elsewhere in the compiler. The TODOs that forced these workarounds are
obsolete.
2026-05-11 18:29:04 -07:00
Angular Robot 2f143bf9c9 docs: update cross-repo adev docs
Updated Angular adev cross repo docs files.
2026-05-11 12:46:59 -07:00
Angular Robot 90c4223aa9 build: update pnpm to v11
See associated pull request for more information.
2026-05-11 12:43:55 -07:00
Douglas Parker 38e26f0759 refactor(core): add "experimental" to WebMCP API names.
WebMCP is still an experimental standard and going through frequent changes in the Chrome implementation and the standards process. As a result, we should be clear about the support status of this API and its overall stability guarantees.
2026-05-11 12:43:06 -07:00
Kam 7a146238ba refactor(compiler-cli): drop @ts-ignore around jsDocParsingMode
The getters and setters for jsDocParsingMode in `host.ts` and
`ts_create_program_driver.ts` were suppressed with @ts-ignore to
support TypeScript 5.2, which lacked the property on `ts.CompilerHost`.
The minimum supported TypeScript is now 6.0, and `jsDocParsingMode`
is part of the public TypeScript API, so the suppressions can go.
2026-05-11 12:40:25 -07:00
Matthieu Riegler 52a848790f docs: update guides to use @Service
In the cases where it was preferable to use `@Service` in place of `@Injectable`
2026-05-11 12:38:23 -07:00
Jessica Janiuk 43a8df9520 ci: update pullapprove
This removes thePunderWoman from active review requests, but leaves passive on.
2026-05-11 12:37:45 -07:00
Ben Hong ef134ac367 docs: add new signal forms field metadata guide
Co-authored-by: Matthieu Riegler <kyro38@gmail.com>
2026-05-11 12:05:27 -07:00
Matthieu Riegler 7360c1da68 docs(docs-infra): improve api docs extraction
This allows us to show the API docs when the jsdoc block is at the top of a overloaded function (and not on the implementation signature).

eg: `injectAsync`
2026-05-11 12:03:39 -07:00
Kam 4ec076e13c docs: add inject() example to "Forwarding injected dependencies"
Lead the section with the recommended `inject()` pattern (child
inherits the property, no `super` forwarding), and keep the existing
constructor DI example after as the alternative. Also fixes a typo
where the verb "class" should read "pass".
2026-05-11 12:02:45 -07:00
Kam 0629e7e505 docs: recommend output() over EventEmitter in reactive forms guide
The "Save form data" step pointed at `EventEmitter` while the rest of
the guide uses modern APIs (e.g. `inject(FormBuilder)`). Swap to
`output()` and align the TODO in the profile-editor example.
2026-05-11 12:02:03 -07:00
SkyZeroZx 538d0a8e93 docs: remove experimental warnings from resource/signal forms documentation 2026-05-11 11:46:08 -07:00
arturovt 7623580378 fix(platform-server): forward BEFORE_APP_SERIALIZED errors to ErrorHandler
Errors thrown by BEFORE_APP_SERIALIZED callbacks were previously logged
via console.warn and silently ignored. This meant failures such as
TransferState.toJson() encountering a circular reference would go
unreported in apps that use a custom ErrorHandler (e.g. Sentry).

Errors are now forwarded to the application's ErrorHandler, making them
visible through whatever reporting mechanism the app has configured.
The render continues to completion after the error is reported.

Closes #65811
2026-05-08 15:10:09 -06:00
Kam 8b46492b7e docs: fix two 404 links in the roadmap
"Introduce built-in control flow" => guide/templates/control-flow (was
the now-removed next.angular.dev/essentials/conditionals-and-loops),
and "Improve documentation and schematics for standalone components"
=> essentials/components (was the bare `components`, not an adev route).
2026-05-08 15:05:40 -06:00
Angular Robot 80632a9f97 build: update dependency bazel to v8.7.0
See associated pull request for more information.
2026-05-08 09:58:39 -06:00
Alan Agius b3de3af0dd docs: remove note regarding lack of support for ng test --debug in browser mode
This is no longer the case.

Closes #68621
2026-05-08 09:57:08 -06:00
Matthew Beck 38b2bede60 docs: release notes for the v22.0.0-next.12 release 2026-05-08 09:24:20 -06:00
Kristiyan Kostadinov c72ebcb1ad fix(core): allow service with factory on abstract classes
Fixes that setting a `@Service` with a `factory` on an abstract class was resulting in a compilation error.
2026-05-08 10:16:15 +02:00
Michael Small 89ee8a8162 docs: fix signal forms async validator typings
docs: add response types for form async `onSuccess`

docs: set defined fallback for async validator params

docs: replace `this.` w/`const`

docs: give fallback string for form async validators

docs: replace `onError` overwritten by `onSuccess`

docs: use `undefined!` for now w/async validators

chore: lint form's `async-operations.md`
2026-05-07 18:17:57 -06:00
SkyZeroZx a0b998e293 docs(docs-infra): use signals & improve types
Use signals to avoid markForCheck.

Simplify takeUntilDestroyed usage by relying on implicit DestroyRef.

Improve type safety by typing inject(ElementRef).
2026-05-07 18:17:29 -06:00
SkyZeroZx 307723a352 docs: add documentation for de-duplicate host directives 2026-05-07 17:53:42 -06:00
Matthieu Riegler a7dab601fa refactor(core): use the @Service decorator where possible.
A few bytes to win.
Added only on the services that don't rely on constructor DI.
2026-05-07 17:03:30 -06:00
Michael Small 7b4791f474 docs: add FormField/FormRoot imports + move comment w/backticks 2026-05-07 16:56:45 -06:00
Michael Small 44c0293a3e docs: fix applyWhenValue form example 2026-05-07 16:54:06 -06:00
Michael Small 0ef43c5ff3 docs: rename outdated validateTree example's model 2026-05-07 16:53:41 -06:00
Angular Robot 28e7bfaf77 docs: update cross-repo adev docs
Updated Angular adev cross repo docs files.
2026-05-07 16:51:57 -06:00
Andrew Scott 932a163cb6 refactor(compiler-cli): fix path normalization and trailing comments (#68454)
Ensure paths are normalized before comparison and key generation in tcb_adapter.ts to avoid failures on Windows.
Ensure a newline before appending imports in TypeCheckFile.render to prevent trailing comments from neutralizing them.

PR Close #68454
2026-05-07 15:42:33 -07:00
Andrew Scott 4f9c824dd9 feat(language-service): Typecheck templates which would require inline typecheck blocks (#68454)
This change updates the language service to generate TCBs for templates that would previously
have required inlining. The new strategy is to copy the original source and then do inlining
in the external TCB. This allows language features and type-checking in templates of non-exported
classes (such as test components) or classes with local, non exported dependencies.

PR Close #68454
2026-05-07 15:42:33 -07:00
Andrew Scott 7f0265e43a feat(language-service): compile non-exported classes if standalone (#68454)
Langauge service previously never compiled non-exported classes. This avoided issues
where test modules would cause diagnostic noise due to components appearing in
declarations of two modules, for example. This change updates the logic to ensure
non-exported, but standalone classes _are_ still compiled.

fixes #65515

PR Close #68454
2026-05-07 15:42:32 -07:00
Angular Robot 3ac11a5e02 build: update pnpm to v10.33.4
See associated pull request for more information.
2026-05-07 16:40:35 -06:00
Angular Robot 827781ea12 build: update all non-major dependencies
See associated pull request for more information.
2026-05-07 16:39:49 -06:00
Angular Robot 17d8be4a76 build: update bazel dependencies
See associated pull request for more information.
2026-05-07 16:37:18 -06:00
Alan Agius 60552a73e8 fix(platform-server): add allowedHosts option to renderModule and renderApplication
In server-side rendering (SSR) setups, passing request URLs directly to the lower-level rendering APIs `renderModule` or `renderApplication` can expose applications to Server-Side Request Forgery (SSRF) or Host Header Injection attacks via absolute-form request URLs.
To mitigate these vulnerabilities at the framework layer, this commit introduces the `allowedHosts` option to `PlatformConfig` (supporting exact hostnames, wildcards like `*.example.com`, or `*` to allow all).

During platform initialization inside `createServerPlatform`, the hostname of the request `url` is validated against the `allowedHosts` list. If the hostname is not authorized, bootstrap immediately throws a host validation error, preventing unauthorized rendering and silent SSRF bypasses.

Closes #68436
2026-05-07 16:30:03 -06:00
Angular Robot 3bf1b10bcf build: update all github actions
See associated pull request for more information.
2026-05-07 16:28:57 -06:00
Kristiyan Kostadinov 1f238ab567 fix(docs-infra): switch remaining adev services to @Service
Reworks all the remaining injectables in adev to use `@Service`.
2026-05-07 16:23:26 -06:00
Matthew Beck b1699da827 test: remove invalid css that was causing issues with the postcss parser
These tests happened to use garbage "{c}" declaration lists which caused
the parser to choke. Given that we already have tests demonstrating
similar behavior and that's not what these tests were meant to
demonstrate, I've updated them to use empty declaration lists.
2026-05-07 16:20:16 -06:00
Alan Agius 5b421c61cd fix(core): disallow event attribute bindings in host bindings unconditionally
Moves the event attribute validation check outside of `ngDevMode` in the `elementAttributeInternal` instruction to ensure that bindings to event attributes like `on*` are always blocked at runtime.
2026-05-07 16:19:22 -06:00
Andrew Scott bc655d006f refactor(compiler): Update indexer API to be generic
Rather than requiring TS AST in the indexer API, this update makes it generic with adapters to provide necessary information. This allows other analysis pipelines that don't use TS AST to work with the indexer.
2026-05-07 16:16:59 -06:00
Kam ed333c3992 docs: normalize product name casing across docs
Several user-facing docs, tooltips, and tutorial code samples used
non-canonical spellings of product names. This normalizes them to
the form each project uses for its own brand.
2026-05-07 16:09:44 -06:00