Skip to content

chore(deps-dev): bump postcss from 8.5.16 to 8.5.23 in /frontend - #78

Merged
pacphi merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/postcss-8.5.18
Aug 9, 2026
Merged

chore(deps-dev): bump postcss from 8.5.16 to 8.5.23 in /frontend#78
pacphi merged 1 commit into
mainfrom
dependabot/npm_and_yarn/frontend/postcss-8.5.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 2, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.16 to 8.5.23.

Release notes

Sourced from postcss's releases.

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).
Changelog

Sourced from postcss's changelog.

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 2, 2026
@pacphi

pacphi commented Aug 2, 2026

Copy link
Copy Markdown
Owner

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

pacphi added a commit that referenced this pull request Aug 9, 2026
… CI (#79)

- Update crossbeam-epoch 0.9.18 -> 0.9.20 (RUSTSEC-2026-0204)
- Update rkyv 0.8.16 -> 0.8.17 (RUSTSEC-2026-0233/0234/0235)
- Ignore RUSTSEC-2026-0235 in .cargo/audit.toml for the remaining
  rkyv 0.7.46 lockfile entry: rust_decimal's unused optional legacy
  feature, never compiled, no patched 0.7.x exists

Unblocks the Backend Security Audit gate failing on all PRs (e.g. #78).
@pacphi

pacphi commented Aug 9, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.16 to 8.5.23.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.16...8.5.23)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.18
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump postcss from 8.5.16 to 8.5.18 in /frontend chore(deps-dev): bump postcss from 8.5.16 to 8.5.23 in /frontend Aug 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/postcss-8.5.18 branch from 8e62a1d to 84d735e Compare August 9, 2026 22:39
@github-actions

github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

📊 Coverage Report

Component Coverage Status
Backend N/A%
Frontend N/A%
Overall N/A%

Coverage Thresholds

  • 🟢 Green: ≥ 80% (target)
  • 🟡 Yellow: 60-79% (acceptable)
  • 🔴 Red: < 60% (needs improvement)

Coverage reports generated by CI workflow

@pacphi
pacphi merged commit 0e5aafa into main Aug 9, 2026
16 checks passed
@pacphi
pacphi deleted the dependabot/npm_and_yarn/frontend/postcss-8.5.18 branch August 9, 2026 23:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant