merge release-9.0.2 - #31421
Merged
Merged
Conversation
v9.0.1 --------- Co-authored-by: ionitron <hi@ionicframework.com>
This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [github/codeql-action](https://redirect.github.com/github/codeql-action) | action | patch | `v4.37.8` → `v4.37.9` | --- ### Release Notes <details> <summary>github/codeql-action (github/codeql-action)</summary> ### [`v4.37.9`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.9) [Compare Source](https://redirect.github.com/github/codeql-action/compare/v4.37.8...v4.37.9) - Update default CodeQL bundle version to [2.26.4](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4). [#​4106](https://redirect.github.com/github/codeql-action/pull/4106) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "every weekday before 11am" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Never, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/ionic-team/ionic-framework). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40Ni4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@axe-core/playwright](https://redirect.github.com/dequelabs/axe-core-npm) | [`^4.12.1` → `^4.13.0`](https://renovatebot.com/diffs/npm/@axe-core%2fplaywright/4.12.1/4.13.0) |  |  | --- ### Release Notes <details> <summary>dequelabs/axe-core-npm (@​axe-core/playwright)</summary> ### [`v4.13.0`](https://redirect.github.com/dequelabs/axe-core-npm/compare/5f587f3a6a8aebfd1ca1bfdde5d93d6b4e1abe8f...70dca949a4e55e2fb83e4e6896fbbf788c56b6fd) [Compare Source](https://redirect.github.com/dequelabs/axe-core-npm/compare/5f587f3a6a8aebfd1ca1bfdde5d93d6b4e1abe8f...v4.13.0) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "every weekday before 11am" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Never, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/ionic-team/ionic-framework). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> --------- Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com> Co-authored-by: Maria Hutt <thetaPC@users.noreply.github.com>
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [@capacitor/core](https://capacitorjs.com) ([source](https://redirect.github.com/ionic-team/capacitor)) | [`8.5.0` → `8.5.1`](https://renovatebot.com/diffs/npm/@capacitor%2fcore/8.5.0/8.5.1) |  |  | --- ### Release Notes <details> <summary>ionic-team/capacitor (@​capacitor/core)</summary> ### [`v8.5.1`](https://redirect.github.com/ionic-team/capacitor/blob/HEAD/CHANGELOG.md#851-2026-08-31) [Compare Source](https://redirect.github.com/ionic-team/capacitor/compare/8.5.0...8.5.1) ##### Bug Fixes - block navigation to the internal HTTP proxy path ([ee586ae](https://redirect.github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922)) - **cli:** use POSIX paths in CapApp-SPM Package.swift ([#​8549](https://redirect.github.com/ionic-team/capacitor/issues/8549)) ([5e5bb3b](https://redirect.github.com/ionic-team/capacitor/commit/5e5bb3befc312477900252ab07e23b596f8cb0d1)) - **core:** prevent removeListener from removing wrong listener ([#​8271](https://redirect.github.com/ionic-team/capacitor/issues/8271)) ([5ac4dd6](https://redirect.github.com/ionic-team/capacitor/commit/5ac4dd613ae989d8dc8738ea25b77efbd4fa21fe)) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "every weekday before 11am" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Never, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/ionic-team/ionic-framework). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40OS4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==--> Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Issue number: resolves #31406 --------- ## What is the current behavior? The `ion-router-outlet` and `ion-tabs` components didn't declare a `changeDetection` strategy, so the Angular partial linker filled one in. An Angular 22 linker fills in `OnPush` when our emitted declaration is stamped 22 or later, while Angular 18 through 21 linkers fill in `Default`. Bumping this package's own Angular version to 22 was enough to flip both components for every Angular 22 consumer. A clean `OnPush` view stops a tick traversing into anything below it, so on Angular 22 with Zone.js the routed page inside the outlet never re-rendered. State set as a plain field after an `await` stayed stale. ## What is the new behavior? Every `@Component` in `packages/angular/src` now declares its strategy explicitly, so the linker can't pick one for us. The `ion-router-outlet` and `ion-tabs` components are `Default` because routed pages are created inside their own views; everything else is `OnPush`, including `ion-nav`, whose pages the delegate attaches as root views instead. ## Does this introduce a breaking change? - [ ] Yes - [x] No ## Other information This PR also adds an ng22-zone app to prevent future regressions like this one. ## Current dev build: ``` 9.0.2-dev.11788201761.1a20dc3a ```
## What is the current behavior? 1. Missed code completion for imported Ionic Vue components in WebStorm a. Reason - invalid Web Types for `@ionic/vue` b. Related issue - [WEB-53833](https://youtrack.jetbrains.com/issue/WEB-53833) ## What is the new behavior? 1. Fine code completion for imported Ionic Vue components in WebStorm ## Does this introduce a breaking change? - [ ] Yes - [x] No --------- Co-authored-by: ShaneK <shane@shanessite.net>
## What is the current behavior?
`sanitizeDOMString` (`core/src/utils/sanitization/index.ts`) blocks
untrusted HTML containing `onload=` before it reaches `innerHTML`,
because `onload` can fire synchronously while the string is being parsed
into the working document fragment — before the later
attribute-allowlist pass runs. The check is a plain lowercase substring
match (`untrustedString.includes('onload=')`), so it misses `onLoad=`,
`ONLOAD=`, or `onload =` (whitespace before `=`) even though HTML parses
all of those as the same event handler.
## What is the new behavior?
-
- Replaced the substring check with a case-insensitive regex that also
tolerates whitespace around `=` (`/onload\s*=/i`), matching how HTML
actually parses attribute names.
- Added a test covering the case and whitespace variants.
## Does this introduce a breaking change?
- [ ] Yes
- [x] No
## Other information
`sanitizeDOMString` is used by `ion-toast`, `ion-loading`, the
`ion-alert` message, `ion-refresher-content`, and
`ion-infinite-scroll-content` to sanitize developer-supplied HTML
strings that may embed end-user input (e.g. another user's display name
rendered in a toast/alert). This closes a gap where a payload like `<svg
onLoad=...>` could bypass the intended guard and reach `innerHTML`
unfiltered.
I didn't find an existing `SECURITY.md` or private vulnerability
reporting channel enabled on this repo, so opening this directly as a PR
with the fix rather than filing a separate public issue describing the
bypass.
---------
Co-authored-by: ShaneK <shane@shanessite.net>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release 9.0.2