build: update dependency pacote to v22 (main) - autoclosed#33386
Closed
angular-robot wants to merge 1 commit into
Closed
build: update dependency pacote to v22 (main) - autoclosed#33386angular-robot wants to merge 1 commit into
angular-robot wants to merge 1 commit into
Conversation
See associated pull request for more information.
There was a problem hiding this comment.
Code Review
This pull request updates the pacote dependency in packages/angular/cli/package.json from version 21.5.1 to 22.0.0. However, this upgrade introduces a breaking change as pacote v22 requires newer Node.js versions, which breaks compatibility with Node.js 18 and 20 LTS currently supported by @angular/cli. It is recommended to revert or defer this dependency update.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
21.5.1→22.0.0Release Notes
npm/pacote (pacote)
v22.0.0Compare Source
pacotenow supports node^22.22.2 || ^24.15.0 || >=26.0.0httpsorgit+httpsprotocol now resolve togit+httpsURLs instead of being switched togit+ssh. Shortcut specs (e.g.github:user/repo,user/repo) andgit+ssh/git://specs are unchanged.Features
09316f5#504 bump to new node engine range (@owlstronaut)2ab74b0#497 strip patchedDependencies from the packed package.json (#497) (@manzoorwanijk)66e7ea7#487 forward globalIgnoreFile option to npm-packlist (@ljharb)Bug Fixes
ce804fb#498 avoid ReDoS in addGitSha committish stripping (#498) (@owlstronaut)1f5f131#494 pass --global=false when preparing git dependencies (@owlstronaut)e0af7f6#486 respect ignoreScripts option for git dependencies (@owlstronaut)12c8c8f#481 fall back to git clone when tarball response is not a valid archive (@babyhuey)61f065a#481 use statusCode instead of constructor name for tarball fallback in git fetcher (@j1mb0-1)6d160c1#434 do not switch to git+ssh for https repository links (#434) (@oldium)Dependencies
371e8b0#504ssri@14.0.0b68c6c2#504sigstore@5.0.057793ab#504proc-log@7.0.033eacc9#504npm-registry-fetch@20.0.1a131916#504npm-pick-manifest@12.0.02b03527#504npm-packlist@11.2.05f8ad42#504npm-package-arg@14.0.0ee3b96d#504cacache@21.0.1033f655#504@npmcli/run-script@11.0.0ddcc738#504@npmcli/promise-spawn@10.0.06a28eb2#504@npmcli/package-json@8.0.05879416#504@npmcli/installed-package-contents@5.0.041ea727#504@npmcli/git@8.0.0Chores
3fc5fd4#504@npmcli/eslint-config@7.0.0(@owlstronaut)7350ab8#504hosted-git-info@10.1.1(@owlstronaut)c7c7d7f#504 template-oss-apply (@owlstronaut)e9ac85e#501 template-oss-apply (@owlstronaut)e184356#501template-oss@5.1.0(@owlstronaut)644ebb6#479 template-oss-apply (@owlstronaut)ee64bea#479@npmcli/template-oss@4.30.0(@owlstronaut)