Skip to content

chore(deps): update dependency postcss to v8.4.31 [security]#110

Open
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-postcss-vulnerability
Open

chore(deps): update dependency postcss to v8.4.31 [security]#110
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-postcss-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Dec 3, 2025

This PR contains the following updates:

Package Change Age Confidence
postcss (source) 8.4.308.4.31 age confidence

PostCSS line return parsing error

CVE-2023-44270 / GHSA-7fh5-64p2-3v2j

More information

Details

An issue was discovered in PostCSS before 8.4.31. It affects linters using PostCSS to parse external Cascading Style Sheets (CSS). There may be \r discrepancies, as demonstrated by @font-face{ font:(\r/*);} in a rule.

This vulnerability affects linters using PostCSS to parse external untrusted CSS. An attacker can prepare CSS in such a way that it will contains parts parsed by PostCSS as a CSS comment. After processing by PostCSS, it will be included in the PostCSS output in CSS nodes (rules, properties) despite being originally included in a comment.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

postcss/postcss (postcss)

v8.4.31

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel
Copy link
Copy Markdown

vercel bot commented Dec 3, 2025

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hygraph-next-enterprise Ready Ready Preview, Comment Mar 5, 2026 9:46am

Request Review

@github-actions
Copy link
Copy Markdown

github-actions bot commented Dec 3, 2025

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed Feb 2, 2026
@renovate renovate bot closed this Feb 2, 2026
@renovate renovate bot deleted the renovate/npm-postcss-vulnerability branch February 2, 2026 05:39
@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed chore(deps): update dependency postcss to v8.4.31 [security] Feb 2, 2026
@renovate renovate bot reopened this Feb 2, 2026
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 4 times, most recently from ac91ce0 to 7f54b77 Compare February 2, 2026 19:55
@renovate renovate bot restored the renovate/npm-postcss-vulnerability branch February 2, 2026 19:57
@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed Mar 3, 2026
@renovate renovate bot closed this Mar 3, 2026
@renovate renovate bot deleted the renovate/npm-postcss-vulnerability branch March 3, 2026 05:51
@renovate renovate bot changed the title chore(deps): update dependency postcss to v8.4.31 [security] - autoclosed chore(deps): update dependency postcss to v8.4.31 [security] Mar 5, 2026
@renovate renovate bot reopened this Mar 5, 2026
@renovate renovate bot force-pushed the renovate/npm-postcss-vulnerability branch 2 times, most recently from 7f54b77 to bf6fa54 Compare March 5, 2026 09:43
@github-actions
Copy link
Copy Markdown

github-actions bot commented Mar 5, 2026

Seems you are using me but didn't get OPENAI_API_KEY seted in Variables/Secrets for this repo. you could follow readme for more information

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants