Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed #76

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Oct 7, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
postcss (source) 8.4.26 -> 8.4.31 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.

This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.


Release Notes

postcss/postcss (postcss)

v8.4.31

Compare Source

v8.4.30

Compare Source

  • Improved source map performance (by Romain Menke).

v8.4.29

Compare Source

  • Fixed Node#source.offset (by Ido Rosenthal).
  • Fixed docs (by Christian Oliff).

v8.4.28

Compare Source

  • Fixed Root.source.end for better source map (by Romain Menke).
  • Fixed Result.root types when process() has no parser.

v8.4.27

Compare Source

  • Fixed Container clone methods types.

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@dpebot
Copy link
Collaborator

dpebot commented Oct 7, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 3d6e5c5 to 0521b71 Compare October 31, 2023 21:11
@dpebot
Copy link
Collaborator

dpebot commented Oct 31, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 0521b71 to e9fcdb7 Compare November 3, 2023 14:53
@dpebot
Copy link
Collaborator

dpebot commented Nov 3, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from e9fcdb7 to 3d56dc9 Compare November 3, 2023 15:14
@dpebot
Copy link
Collaborator

dpebot commented Nov 3, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 3d56dc9 to 8432239 Compare November 30, 2023 16:03
@dpebot
Copy link
Collaborator

dpebot commented Nov 30, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 8432239 to c0d8430 Compare December 4, 2023 21:25
@dpebot
Copy link
Collaborator

dpebot commented Dec 4, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from c0d8430 to c6aa895 Compare December 8, 2023 19:20
@dpebot
Copy link
Collaborator

dpebot commented Dec 8, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from c6aa895 to 9a87a77 Compare December 19, 2023 15:43
@dpebot
Copy link
Collaborator

dpebot commented Dec 19, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 9a87a77 to 0620b89 Compare December 19, 2023 16:06
@dpebot
Copy link
Collaborator

dpebot commented Dec 19, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 0620b89 to aeb7a59 Compare December 19, 2023 17:17
@dpebot
Copy link
Collaborator

dpebot commented Dec 19, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from aeb7a59 to 5b50f98 Compare December 20, 2023 02:33
@dpebot
Copy link
Collaborator

dpebot commented Dec 20, 2023

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 5b50f98 to cc75f35 Compare January 3, 2024 20:30
@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from cc75f35 to dfe541e Compare January 12, 2024 19:44
@dpebot
Copy link
Collaborator

dpebot commented Jan 12, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from dfe541e to 0cccb04 Compare January 12, 2024 20:11
@dpebot
Copy link
Collaborator

dpebot commented Jan 12, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 0cccb04 to c84a74a Compare January 12, 2024 22:33
@dpebot
Copy link
Collaborator

dpebot commented Jan 12, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from c84a74a to 30e1d39 Compare January 13, 2024 02:49
@dpebot
Copy link
Collaborator

dpebot commented Jan 13, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 30e1d39 to ffcf772 Compare January 13, 2024 03:08
@dpebot
Copy link
Collaborator

dpebot commented Jan 13, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from ffcf772 to 33b0f20 Compare January 30, 2024 19:14
@dpebot
Copy link
Collaborator

dpebot commented Jan 30, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 33b0f20 to f538fbf Compare February 3, 2024 02:36
@dpebot
Copy link
Collaborator

dpebot commented Feb 3, 2024

/gcbrun

@renovate-bot renovate-bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] fix(deps): Update dependency postcss to v8.4.31 [SECURITY] Feb 5, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from f538fbf to 662bbfe Compare February 20, 2024 21:30
@dpebot
Copy link
Collaborator

dpebot commented Feb 20, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 662bbfe to 21d0209 Compare February 22, 2024 01:52
@dpebot
Copy link
Collaborator

dpebot commented Feb 22, 2024

/gcbrun

@renovate-bot renovate-bot changed the title fix(deps): Update dependency postcss to v8.4.31 [SECURITY] chore(deps): update dependency postcss to v8.4.31 [security] Feb 22, 2024
@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 21d0209 to 21b9d9f Compare February 23, 2024 16:51
@dpebot
Copy link
Collaborator

dpebot commented Feb 23, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 21b9d9f to 1414dac Compare February 26, 2024 19:25
@dpebot
Copy link
Collaborator

dpebot commented Feb 26, 2024

/gcbrun

@renovate-bot renovate-bot force-pushed the renovate/npm-postcss-vulnerability branch from 1414dac to 743dd16 Compare February 26, 2024 19:27
@dpebot
Copy link
Collaborator

dpebot commented Feb 26, 2024

/gcbrun

@renovate-bot renovate-bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed Mar 12, 2024
@renovate-bot renovate-bot deleted the renovate/npm-postcss-vulnerability branch March 12, 2024 12:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants