Skip to content

merge release-9.0.2 - #31421

Merged
ShaneK merged 9 commits into
9.0.xfrom
release-9.0.2
Sep 2, 2026
Merged

merge release-9.0.2#31421
ShaneK merged 9 commits into
9.0.xfrom
release-9.0.2

Conversation

@ShaneK

@ShaneK ShaneK commented Sep 2, 2026

Copy link
Copy Markdown
Member

Release 9.0.2

thetaPC and others added 9 commits August 26, 2026 11:23
v9.0.1

---------

Co-authored-by: ionitron <hi@ionicframework.com>
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
|
[github/codeql-action](https://redirect.github.com/github/codeql-action)
| action | patch | `v4.37.8` → `v4.37.9` |

---

### Release Notes

<details>
<summary>github/codeql-action (github/codeql-action)</summary>

###
[`v4.37.9`](https://redirect.github.com/github/codeql-action/releases/tag/v4.37.9)

[Compare
Source](https://redirect.github.com/github/codeql-action/compare/v4.37.8...v4.37.9)

- Update default CodeQL bundle version to
[2.26.4](https://redirect.github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4).
[#&#8203;4106](https://redirect.github.com/github/codeql-action/pull/4106)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - "every weekday before 11am"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/ionic-team/ionic-framework).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40Ni4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
|
[@axe-core/playwright](https://redirect.github.com/dequelabs/axe-core-npm)
| [`^4.12.1` →
`^4.13.0`](https://renovatebot.com/diffs/npm/@axe-core%2fplaywright/4.12.1/4.13.0)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@axe-core%2fplaywright/4.13.0?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@axe-core%2fplaywright/4.12.1/4.13.0?slim=true)
|

---

### Release Notes

<details>
<summary>dequelabs/axe-core-npm (@&#8203;axe-core/playwright)</summary>

###
[`v4.13.0`](https://redirect.github.com/dequelabs/axe-core-npm/compare/5f587f3a6a8aebfd1ca1bfdde5d93d6b4e1abe8f...70dca949a4e55e2fb83e4e6896fbbf788c56b6fd)

[Compare
Source](https://redirect.github.com/dequelabs/axe-core-npm/compare/5f587f3a6a8aebfd1ca1bfdde5d93d6b4e1abe8f...v4.13.0)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - "every weekday before 11am"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/ionic-team/ionic-framework).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yNC4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDYuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

---------

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Maria Hutt <thetaPC@users.noreply.github.com>
This PR contains the following updates:

| Package | Change |
[Age](https://docs.renovatebot.com/merge-confidence/) |
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [@capacitor/core](https://capacitorjs.com)
([source](https://redirect.github.com/ionic-team/capacitor)) | [`8.5.0`
→
`8.5.1`](https://renovatebot.com/diffs/npm/@capacitor%2fcore/8.5.0/8.5.1)
|
![age](https://developer.mend.io/api/mc/badges/age/npm/@capacitor%2fcore/8.5.1?slim=true)
|
![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/@capacitor%2fcore/8.5.0/8.5.1?slim=true)
|

---

### Release Notes

<details>
<summary>ionic-team/capacitor (@&#8203;capacitor/core)</summary>

###
[`v8.5.1`](https://redirect.github.com/ionic-team/capacitor/blob/HEAD/CHANGELOG.md#851-2026-08-31)

[Compare
Source](https://redirect.github.com/ionic-team/capacitor/compare/8.5.0...8.5.1)

##### Bug Fixes

- block navigation to the internal HTTP proxy path
([ee586ae](https://redirect.github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922))
- **cli:** use POSIX paths in CapApp-SPM Package.swift
([#&#8203;8549](https://redirect.github.com/ionic-team/capacitor/issues/8549))
([5e5bb3b](https://redirect.github.com/ionic-team/capacitor/commit/5e5bb3befc312477900252ab07e23b596f8cb0d1))
- **core:** prevent removeListener from removing wrong listener
([#&#8203;8271](https://redirect.github.com/ionic-team/capacitor/issues/8271))
([5ac4dd6](https://redirect.github.com/ionic-team/capacitor/commit/5ac4dd613ae989d8dc8738ea25b77efbd4fa21fe))

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - "every weekday before 11am"
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Never, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/ionic-team/ionic-framework).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC40OS4wIiwidXBkYXRlZEluVmVyIjoiNDQuNDkuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Issue number: resolves #31406

---------

## What is the current behavior?

The `ion-router-outlet` and `ion-tabs` components didn't declare a
`changeDetection` strategy, so the Angular partial linker filled one in.
An Angular 22 linker fills in `OnPush` when our emitted declaration is
stamped 22 or later, while Angular 18 through 21 linkers fill in
`Default`. Bumping this package's own Angular version to 22 was enough
to flip both components for every Angular 22 consumer.

A clean `OnPush` view stops a tick traversing into anything below it, so
on Angular 22 with Zone.js the routed page inside the outlet never
re-rendered. State set as a plain field after an `await` stayed stale.

## What is the new behavior?

Every `@Component` in `packages/angular/src` now declares its strategy
explicitly, so the linker can't pick one for us. The `ion-router-outlet`
and `ion-tabs` components are `Default` because routed pages are created
inside their own views; everything else is `OnPush`, including
`ion-nav`, whose pages the delegate attaches as root views instead.

## Does this introduce a breaking change?

- [ ] Yes
- [x] No

## Other information

This PR also adds an ng22-zone app to prevent future regressions like
this one.

## Current dev build:
```
9.0.2-dev.11788201761.1a20dc3a
```
## What is the current behavior?
1. Missed code completion for imported Ionic Vue components in WebStorm
  a. Reason - invalid Web Types for `@ionic/vue`
b. Related issue -
[WEB-53833](https://youtrack.jetbrains.com/issue/WEB-53833)

## What is the new behavior?
1. Fine code completion for imported Ionic Vue components in WebStorm

## Does this introduce a breaking change?

- [ ] Yes
- [x] No

---------

Co-authored-by: ShaneK <shane@shanessite.net>
## What is the current behavior?

`sanitizeDOMString` (`core/src/utils/sanitization/index.ts`) blocks
untrusted HTML containing `onload=` before it reaches `innerHTML`,
because `onload` can fire synchronously while the string is being parsed
into the working document fragment — before the later
attribute-allowlist pass runs. The check is a plain lowercase substring
match (`untrustedString.includes('onload=')`), so it misses `onLoad=`,
`ONLOAD=`, or `onload =` (whitespace before `=`) even though HTML parses
all of those as the same event handler.

## What is the new behavior?

-
- Replaced the substring check with a case-insensitive regex that also
tolerates whitespace around `=` (`/onload\s*=/i`), matching how HTML
actually parses attribute names.
- Added a test covering the case and whitespace variants.

## Does this introduce a breaking change?

- [ ] Yes
- [x] No

## Other information

`sanitizeDOMString` is used by `ion-toast`, `ion-loading`, the
`ion-alert` message, `ion-refresher-content`, and
`ion-infinite-scroll-content` to sanitize developer-supplied HTML
strings that may embed end-user input (e.g. another user's display name
rendered in a toast/alert). This closes a gap where a payload like `<svg
onLoad=...>` could bypass the intended guard and reach `innerHTML`
unfiltered.

I didn't find an existing `SECURITY.md` or private vulnerability
reporting channel enabled on this repo, so opening this directly as a PR
with the fix rather than filing a separate public issue describing the
bypass.

---------

Co-authored-by: ShaneK <shane@shanessite.net>
@ShaneK
ShaneK requested a review from a team as a code owner September 2, 2026 19:26
@ShaneK
ShaneK requested review from brandyscarney and removed request for a team September 2, 2026 19:26
@github-actions github-actions Bot added package: core @ionic/core package package: angular @ionic/angular package package: vue @ionic/vue package package: react @ionic/react package labels Sep 2, 2026
@vercel

vercel Bot commented Sep 2, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
ionic-framework Ready Ready Preview Sep 2, 2026 7:32pm UTC

Request Review

@ShaneK
ShaneK merged commit 2032719 into 9.0.x Sep 2, 2026
106 checks passed
@ShaneK
ShaneK deleted the release-9.0.2 branch September 2, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

package: angular @ionic/angular package package: core @ionic/core package package: react @ionic/react package package: vue @ionic/vue package

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants