Backport esbuild and @babel/core security bumps to the 21.2.x LTS branch
envgap__angular__angular-cli-33420
01 / FAILURE SIGNATURE
As reported upstream
### Exception or Error
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
e86d58a128725eee9dd63dcd2ccd35b8ee4706f3- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
angular/angular-cli #33420 · read the original issue
### Command build ### Is this a regression? - [ ] Yes, this behavior used to work in the previous version ### The previous version in which this bug was not present was _No response_ ### Description `@angular/build` on the `21.2.x` branch still depends on two transitives with published GitHub security advisories: | Transitive | Version on `21.2.x` | Advisory | Severity | Patched in | |---|---|---|---|---| | `esbuild` | `0.27.3` | [GHSA-g7r4-m6w7-qqqr](https://github.com/advisories/GHSA-g7r4-m6w7-qqqr) — arbitrary file read via dev-server on Windows | CVSS 3.1: **2.5 (Low)** | `0.28.1` | | `@babel/core` | `7.29.0` | [GHSA-4x5r-pxfx-6jf8](https://github.com/advisories/GHSA-4x5r-pxfx-6jf8) / CVE-2026-49356 — arbitrary file read via `sourceMappingURL` | CVSS 3.1: **3.2 (Low)** | `7.29.6` | Source confirmed on the branch: https://github.com/angular/angular-cli/blob/21.2.x/packages/angular/build/package.json Real-world impact for consumers is bounded — both are dev/build-time, and the esbuild advisory is Windows-only. The request here is procedural: these surface on every `npm audit` against an Angular 21 project, and downstream consumers (especially those with security-scanning gates in CI) cannot resolve them without forking or moving to v22. ## Precedent for backports Backports of this exact shape have already happened recently, including on this branch: - **#33408** — `fix(@angular/build): bump vite to 7.3.5`, base `21.2.x`, merged 2026-06-18. This is the freshest precedent: a security-driven transitive bump landed on `21.2.x` yesterday. - **#33384 / #33385** — Renovate bumps of `esbuild` / `esbuild-wasm` to `0.28.1` on `22.0.x`, merged 2026-06-16. These are the exact bumps being requested here, just on the active branch. - **#33004** — `fix(@angular/build): update esbuild to 0.28.0`, base `20.3.x`, merged 2026-04-14, referencing #32975 (esbuild CVE, triaged `severity6: security`). - **#33003** — same fix on base `19.2.x`, merged the same day. - **#32945** — earlier vite advisory report on `@angular/build@21.2.6`, similarly triaged and resolved. Per Angular's release policy at https://angular.dev/reference/releases, a fix qualifies for an LTS branch if it addresses *"a newly identified security vulnerability"*, which the precedent issues above were treated as. ### Minimal Reproduction ``` npx -p @angular/cli@21.2.16 -- ng new repro --defaults --skip-git --skip-install cd repro npm i npm audit ``` `npm audit` reports the advisories above against transitives of `@angular/build`. The same audit run against a project on `@angular/cli@22.0.x` (post-#33384/#33385) shows the esbuild line cleared. (Note: `vite` is already addressed by #33408 on the `21.2.x` branch and will clear with the next 21.2.x release.) ### Exception or Error ```text n/a — not a runtime error; advisories surface in `npm audit` only. ``` ### Your Environment ```text Angular CLI: 21.2.16 Node: 24.0.0 Package Manager: npm 11.x OS: darwin arm64 Angular: 21.2.17 ... @angular/build 21.2.16 ... esbuild 0.27.3 ... @babel/core 7.29.0 ``` ### Anything else relevant? Thanks for considering — and thanks for the prompt vite backport in #33408 yesterday, much appreciated.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]