Skip to content

chore(deps): bump postcss to ^8.5.10#6058

Merged
antonis merged 2 commits intomainfrom
antonis/bump-postcss
Apr 28, 2026
Merged

chore(deps): bump postcss to ^8.5.10#6058
antonis merged 2 commits intomainfrom
antonis/bump-postcss

Conversation

@antonis
Copy link
Copy Markdown
Contributor

@antonis antonis commented Apr 28, 2026

Unscoped resolution to bump postcss from 8.4.41 to 8.5.12, fixing XSS via unescaped </style> in CSS stringify output.

Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/512

Fixes Dependabot alert for XSS via unescaped </style> in CSS stringify output.

Dev-only dependency.

https://github.com/getsentry/sentry-react-native/security/dependabot/512

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@antonis antonis marked this pull request as ready for review April 28, 2026 10:06
Copy link
Copy Markdown
Collaborator

@lucas-zimerman lucas-zimerman left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! after ci test passes

@antonis antonis added the ready-to-merge Triggers the full CI test suite label Apr 28, 2026
@antonis antonis merged commit 92c92f5 into main Apr 28, 2026
69 of 93 checks passed
@antonis antonis deleted the antonis/bump-postcss branch April 28, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-to-merge Triggers the full CI test suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants