Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency postcss to 8.2.13 [SECURITY] #889

Closed
wants to merge 1 commit into from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jan 16, 2022

WhiteSource Renovate

This PR contains the following updates:

Package Change
postcss 7.0.27 -> 8.2.13
postcss 7.0.17 -> 8.2.13
postcss 7.0.14 -> 8.2.13
postcss 6.0.23 -> 8.2.13
postcss 7.0.32 -> 8.2.13

GitHub Vulnerability Alerts

CVE-2021-23382

The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of Service (ReDoS) via getAnnotationURL() and loadAnnotation() in lib/previous-map.js. The vulnerable regexes are caused mainly by the sub-pattern /*\s* sourceMappingURL=(.*).

CVE-2021-23368

The npm package postcss from 7.0.0 and before versions 7.0.36 and 8.2.10 is vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.


Configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, click this checkbox.

This PR has been generated by WhiteSource Renovate. View repository job log here.

Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38357 lines exceeds the maximum allowed for the inline comments feature.

@codecov
Copy link

codecov bot commented Jan 16, 2022

Codecov Report

Merging #889 (cbec46f) into master (a6c6f46) will not change coverage.
The diff coverage is n/a.

Impacted file tree graph

@@           Coverage Diff           @@
##           master     #889   +/-   ##
=======================================
  Coverage   47.54%   47.54%           
=======================================
  Files           3        3           
  Lines          61       61           
  Branches        8        8           
=======================================
  Hits           29       29           
  Misses         28       28           
  Partials        4        4           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update a6c6f46...cbec46f. Read the comment docs.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from 2f3e3ff to 98081bf Compare January 16, 2022 22:27
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from 98081bf to e310818 Compare January 17, 2022 07:30
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from e310818 to 72b152c Compare January 17, 2022 08:23
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from 72b152c to cbc2f67 Compare January 17, 2022 09:24
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from cbc2f67 to a75fdd1 Compare January 17, 2022 10:24
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from a75fdd1 to fa20857 Compare January 17, 2022 11:24
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from fa20857 to 98f852b Compare January 17, 2022 13:41
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from 98f852b to 08b3ebd Compare January 17, 2022 14:41
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@renovate renovate bot force-pushed the renovate/root/npm-postcss-vulnerability branch from 08b3ebd to cbec46f Compare January 17, 2022 20:37
Copy link

@codeclimate codeclimate bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR diff size of 38127 lines exceeds the maximum allowed for the inline comments feature.

@codeclimate
Copy link

codeclimate bot commented Jan 17, 2022

Code Climate has analyzed commit cbec46f and detected 0 issues on this pull request.

View more on Code Climate.

@satanTime satanTime closed this Jan 17, 2022
@renovate
Copy link
Contributor Author

renovate bot commented Jan 17, 2022

Renovate Ignore Notification

As this PR has been closed unmerged, Renovate will now ignore this update (8.2.13). You will still receive a PR once a newer version is released, so if you wish to permanently ignore this dependency, please add it to the ignoreDeps array of your renovate config.

If this PR was closed by mistake or you changed your mind, you can simply rename this PR and you will soon get a fresh replacement PR opened.

@renovate renovate bot deleted the renovate/root/npm-postcss-vulnerability branch January 17, 2022 21:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants