Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 7, 2023

This PR contains the following updates:

Package Change Age Confidence
postcss (source) 8.4.17 -> 8.4.31 age confidence

GitHub Vulnerability Alerts

CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.

This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.


Release Notes

postcss/postcss (postcss)

v8.4.31

Compare Source

v8.4.30

Compare Source

  • Improved source map performance (by Romain Menke).

v8.4.29

Compare Source

  • Fixed Node#source.offset (by Ido Rosenthal).
  • Fixed docs (by Christian Oliff).

v8.4.28

Compare Source

  • Fixed Root.source.end for better source map (by Romain Menke).
  • Fixed Result.root types when process() has no parser.

v8.4.27

Compare Source

  • Fixed Container clone methods types.

v8.4.26

Compare Source

  • Fixed clone methods types.

v8.4.25

Compare Source

v8.4.24

Compare Source

  • Fixed Plugin types.

v8.4.23

Compare Source

  • Fixed warnings in TypeDoc.

v8.4.22

Compare Source

  • Fixed TypeScript support with node16 (by Remco Haszing).

v8.4.21

Compare Source

  • Fixed Input#error types (by Aleks Hudochenkov).

v8.4.20

Compare Source

  • Fixed source map generation for childless at-rules like @layer.

v8.4.19

Compare Source

  • Fixed whitespace preserving after AST transformations (by Romain Menke).

v8.4.18

Compare Source

  • Fixed an error on absolute: true with empty sourceContent (by Rene Haas).

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies label Oct 7, 2023
@vercel
Copy link

vercel bot commented Oct 7, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
supabase-graphql-example ❌ Failed (Inspect) Jul 27, 2025 0:00am
@renovate renovate bot changed the title fix(deps): update dependency postcss to v8.4.31 [security] fix(deps): update dependency postcss to v8.4.31 [security] - autoclosed Dec 22, 2023
@renovate renovate bot closed this Dec 22, 2023
@renovate renovate bot deleted the renovate/npm-postcss-vulnerability branch December 22, 2023 06:56
@renovate renovate bot changed the title fix(deps): update dependency postcss to v8.4.31 [security] - autoclosed fix(deps): update dependency postcss to v8.4.31 [security] Dec 22, 2023
@renovate renovate bot reopened this Dec 22, 2023
@renovate renovate bot restored the renovate/npm-postcss-vulnerability branch December 22, 2023 10:55
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 90c6681 to efc5062 Compare December 22, 2023 10:56
@renovate renovate bot changed the title fix(deps): update dependency postcss to v8.4.31 [security] fix(deps): update dependency postcss to v8.4.31 [security] - autoclosed Jan 23, 2024
@renovate renovate bot closed this Jan 23, 2024
@renovate renovate bot deleted the renovate/npm-postcss-vulnerability branch January 23, 2024 16:37
@renovate renovate bot changed the title fix(deps): update dependency postcss to v8.4.31 [security] - autoclosed fix(deps): update dependency postcss to v8.4.31 [security] Jan 23, 2024
@renovate renovate bot reopened this Jan 23, 2024
@renovate renovate bot restored the renovate/npm-postcss-vulnerability branch January 23, 2024 19:44
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from efc5062 to d51df68 Compare January 23, 2024 19:45
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from d51df68 to 55f7059 Compare July 27, 2025 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

1 participant