Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Oct 8, 2023

This PR contains the following updates:

Package Change Age Confidence
postcss (source) 8.4.29 -> 8.4.31 age confidence

GitHub Vulnerability Alerts

CVE-2023-44270

An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.

This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.


Release Notes

postcss/postcss (postcss)

v8.4.31

Compare Source

v8.4.30

Compare Source

  • Improved source map performance (by Romain Menke).

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies label Oct 8, 2023
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 785a2ec to ee15151 Compare January 23, 2025 18:25
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from ee15151 to 4dcb803 Compare January 30, 2025 19:37
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 4dcb803 to 20631e3 Compare March 3, 2025 16:56
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 40fe7ac to 3b8adaf Compare March 17, 2025 12:29
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 3b8adaf to cdd4bda Compare April 1, 2025 10:17
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from cdd4bda to 7dc866c Compare June 4, 2025 09:32
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch from 7dc866c to b507409 Compare June 22, 2025 12:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant