Chore(deps): Bump postcss from 8.5.20 to 8.5.25 in /src/frontend - #1423
Chore(deps): Bump postcss from 8.5.20 to 8.5.25 in /src/frontend#1423dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.20 to 8.5.25. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.20...8.5.25) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.25 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
Files not reviewed (1)
- src/frontend/pnpm-lock.yaml: Generated file
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
✅ Tracked by automated-security as the green remediation for the aspire.dev frontend postcss advisory (GHSA-fxqj-rqcc-2cmp → 8.5.25, clears alert #109). All checks pass — this is the canonical vehicle for the postcss cluster. The brace-expansion → 5.0.9 advisory (GHSA-rgw5-rvv9-x895, alert #108) is deferred: 5.0.9 is not yet on this environment's package mirror and the public npm registry is unreachable here, so it cannot be reproduced locally. It is carried by group PR #1421 and will otherwise be applied by Dependabot/CI. |
Raise pnpm override floors and refresh the lockfile to clear two open Dependabot alerts in src/frontend: - brace-expansion 5.0.8 -> 5.0.9 (HIGH, GHSA-rgw5-rvv9-x895): DoS via unbounded intermediate arrays (bypasses CVE-2026-14257 mitigation). - postcss 8.5.20 -> 8.5.25 (MEDIUM, GHSA-fxqj-rqcc-2cmp): arbitrary .map read via attacker-controlled sourceMappingURL when from unset. Lockfile changes folded from Dependabot #1423 (postcss) plus the isolated brace-expansion entry from #1421; no other package versions changed. Override floors in pnpm-workspace.yaml match the lock. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
Superseded by #1431 (canonical #1431 delivers the same Closing as superseded — no action lost. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps postcss from 8.5.20 to 8.5.25.
Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
08c989cRelease 8.5.25 version24f6814Fix 8.5.17 visitor regressionf2fa53fAdd supply chain security requirement to PostCSS plugin guide10edf0bfix: return empty array for empty string in list.split (#2121)0ebe8adRelease 8.5.24 version73218c6Update dependencies9a114f6Preserve the BOM when stringifying (#2119)9069261Fix types checkeb9e1feRelease 8.5.23 version9d19c78Update dependenciesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.