-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed #76
Closed
renovate-bot
wants to merge
1
commit into
GoogleCloudPlatform:main
from
renovate-bot:renovate/npm-postcss-vulnerability
Closed
chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed #76
renovate-bot
wants to merge
1
commit into
GoogleCloudPlatform:main
from
renovate-bot:renovate/npm-postcss-vulnerability
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate-bot
requested review from
xsxm,
ivanmkc,
balajismaniam and
donmccasland
as code owners
October 7, 2023 23:34
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
October 31, 2023 21:11
3d6e5c5
to
0521b71
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
November 3, 2023 14:53
0521b71
to
e9fcdb7
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
November 3, 2023 15:14
e9fcdb7
to
3d56dc9
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
November 30, 2023 16:03
3d56dc9
to
8432239
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 4, 2023 21:25
8432239
to
c0d8430
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 8, 2023 19:20
c0d8430
to
c6aa895
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 19, 2023 15:43
c6aa895
to
9a87a77
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 19, 2023 16:06
9a87a77
to
0620b89
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 19, 2023 17:17
0620b89
to
aeb7a59
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
December 20, 2023 02:33
aeb7a59
to
5b50f98
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 3, 2024 20:30
5b50f98
to
cc75f35
Compare
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 12, 2024 19:44
cc75f35
to
dfe541e
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 12, 2024 20:11
dfe541e
to
0cccb04
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 12, 2024 22:33
0cccb04
to
c84a74a
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 13, 2024 02:49
c84a74a
to
30e1d39
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 13, 2024 03:08
30e1d39
to
ffcf772
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
January 30, 2024 19:14
ffcf772
to
33b0f20
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 3, 2024 02:36
33b0f20
to
f538fbf
Compare
/gcbrun |
renovate-bot
changed the title
chore(deps): update dependency postcss to v8.4.31 [security]
fix(deps): Update dependency postcss to v8.4.31 [SECURITY]
Feb 5, 2024
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 20, 2024 21:30
f538fbf
to
662bbfe
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 22, 2024 01:52
662bbfe
to
21d0209
Compare
/gcbrun |
renovate-bot
changed the title
fix(deps): Update dependency postcss to v8.4.31 [SECURITY]
chore(deps): update dependency postcss to v8.4.31 [security]
Feb 22, 2024
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 23, 2024 16:51
21d0209
to
21b9d9f
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 26, 2024 19:25
21b9d9f
to
1414dac
Compare
/gcbrun |
renovate-bot
force-pushed
the
renovate/npm-postcss-vulnerability
branch
from
February 26, 2024 19:27
1414dac
to
743dd16
Compare
/gcbrun |
renovate-bot
changed the title
chore(deps): update dependency postcss to v8.4.31 [security]
chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed
Mar 12, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
8.4.26
->8.4.31
GitHub Vulnerability Alerts
CVE-2023-44270
An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be
\r
discrepancies, as demonstrated by@font-face{ font:(\r/*);}
in a rule.This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.
Release Notes
postcss/postcss (postcss)
v8.4.31
Compare Source
\r
parsing to fix CVE-2023-44270.v8.4.30
Compare Source
v8.4.29
Compare Source
Node#source.offset
(by Ido Rosenthal).v8.4.28
Compare Source
Root.source.end
for better source map (by Romain Menke).Result.root
types whenprocess()
has no parser.v8.4.27
Compare Source
Container
clone methods types.Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.