Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 13, 2024

This PR contains the following updates:

Package Change Age Confidence
postcss (source) 8.4.218.4.31 age confidence

GitHub Vulnerability Alerts

CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.

This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.


Release Notes

postcss/postcss (postcss)

v8.4.31

Compare Source

v8.4.30

Compare Source

  • Improved source map performance (by Romain Menke).

v8.4.29

Compare Source

  • Fixed Node#source.offset (by Ido Rosenthal).
  • Fixed docs (by Christian Oliff).

v8.4.28

Compare Source

  • Fixed Root.source.end for better source map (by Romain Menke).
  • Fixed Result.root types when process() has no parser.

v8.4.27

Compare Source

  • Fixed Container clone methods types.

v8.4.26

Compare Source

  • Fixed clone methods types.

v8.4.25

Compare Source

v8.4.24

Compare Source

  • Fixed Plugin types.

v8.4.23

Compare Source

  • Fixed warnings in TypeDoc.

v8.4.22

Compare Source

  • Fixed TypeScript support with node16 (by Remco Haszing).

Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Prague, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Oct 13, 2024
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from b990a6d to 89d1995 Compare October 31, 2024 14:54
@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed Dec 8, 2024
@renovate renovate bot closed this Dec 8, 2024
@renovate renovate bot deleted the renovate/npm-postcss-vulnerability branch December 8, 2024 18:45
@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed chore(deps): update dependency postcss to v8.4.31 [security] Dec 8, 2024
@renovate renovate bot reopened this Dec 8, 2024
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 3 times, most recently from 188158b to d63ddcd Compare December 12, 2024 11:07
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from dfa50d4 to 0c8b73c Compare January 30, 2025 17:38
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 0c8b73c to ebf88e6 Compare February 9, 2025 13:36
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 3 times, most recently from 39c387d to 6999592 Compare March 3, 2025 12:53
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 3 times, most recently from 9a3d61f to 10bca53 Compare March 17, 2025 18:16
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from a4ba92a to 60e24d1 Compare April 1, 2025 10:49
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 60e24d1 to 7300042 Compare April 8, 2025 11:28
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 7300042 to 39f09fb Compare April 24, 2025 10:28
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 7a20c12 to e3c635e Compare May 23, 2025 15:39
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from a61a566 to ee5575f Compare May 28, 2025 07:39
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 4829b5e to 48d4609 Compare June 9, 2025 10:59
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 48d4609 to 6a9c01d Compare June 19, 2025 07:36
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 6a9c01d to 7d5236d Compare June 23, 2025 09:17
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 4 times, most recently from 42c88fe to d44a3dc Compare July 7, 2025 12:59
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from d44a3dc to 1b83db8 Compare July 9, 2025 13:07
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 1b83db8 to ccf6f10 Compare July 17, 2025 15:15
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 41486d0 to a1eafba Compare August 6, 2025 12:12
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 97cfe4b to 61acdf6 Compare August 18, 2025 14:33
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 61acdf6 to 29a4878 Compare August 29, 2025 12:52
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from c915218 to c299e46 Compare October 23, 2025 13:22
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from c299e46 to f9b8621 Compare November 11, 2025 14:47
@coderabbitai
Copy link

coderabbitai bot commented Nov 11, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Comment @coderabbitai help to get the list of available commands and usage tips.

@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 50944eb to a23afbc Compare December 3, 2025 13:46
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from a23afbc to 5cb1c46 Compare December 31, 2025 16:34
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 5cb1c46 to 4bc7eae Compare January 19, 2026 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants