Skip to content

refactor: Bump postcss from 8.5.3 to 8.5.19#3355

Merged
mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/postcss-8.5.14
Jul 13, 2026
Merged

refactor: Bump postcss from 8.5.3 to 8.5.19#3355
mtrezza merged 1 commit into
alphafrom
dependabot/npm_and_yarn/postcss-8.5.14

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 9, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.3 to 8.5.19.

Release notes

Sourced from postcss's releases.

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

8.5.15

  • Fixed declaration parsing performance (by @​homanp).

8.5.14

8.5.13

  • Fixed postcss-scss commend regression.

8.5.12

  • Fixed reading any file via user-generated CSS.
  • Added opts.unsafeMap to disable checks.

8.5.11

  • Fixed nested brackets parsing performance (by @​offset).

8.5.10

  • Fixed XSS via unescaped </style> in non-bundler cases (by @​TharVid).

8.5.9

  • Speed up source map encoding paring in case of the error.

8.5.8

  • Fixed Processor#version.

8.5.7

  • Improved source map annotation cleaning performance (by CodeAnt AI).

8.5.6

  • Fixed ContainerWithChildren type discriminating (by @​Goodwine).

8.5.5

... (truncated)

Changelog

Sourced from postcss's changelog.

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

8.5.15

  • Fixed declaration parsing performance (by @​homanp).

8.5.14

8.5.13

  • Fixed postcss-scss commend regression.

8.5.12

  • Fixed reading any file via user-generated CSS.
  • Added opts.unsafeMap to disable checks.

8.5.11

  • Fixed nested brackets parsing performance (by @​offset).

8.5.10

  • Fixed XSS via unescaped </style> in non-bundler cases (by @​TharVid).

8.5.9

  • Speed up source map encoding paring in case of the error.

... (truncated)

Commits
  • 9543b22 Release 8.5.19 version
  • 3d13bf9 Fix CI on Windows too
  • 00d0dd2 Keep explicitly set raws.before when inserting nodes into root (#2111)
  • 7a05b33 Temporary fix CI
  • 4c0d194 Release 8.5.18 version
  • 92b4e78 Update dependencies
  • 95663d3 Limit where source map can be loaded for security reasons
  • 74e25ae Release 8.5.17 version
  • d1518af Fix Maximum call stack size exceeded error
  • 2421312 Fix linter
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.


Summary by CodeRabbit

  • Chores
    • Updated internal package metadata for nanoid and postcss to newer versions.
    • Refreshed the related dependency references and integrity information.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code labels May 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/postcss-8.5.14 branch from d787619 to 4b37896 Compare May 18, 2026 19:53
@mtrezza

mtrezza commented Jul 13, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.3 to 8.5.19.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.3...8.5.19)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.14
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title refactor: Bump postcss from 8.5.3 to 8.5.14 refactor: Bump postcss from 8.5.3 to 8.5.19 Jul 13, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/postcss-8.5.14 branch from 4b37896 to 9b513fb Compare July 13, 2026 21:27
@mtrezza

mtrezza commented Jul 13, 2026

Copy link
Copy Markdown
Member

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Jul 13, 2026

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

The lockfile updates nanoid to 3.3.16 and postcss to 8.5.19, including their resolved URLs and integrity hashes. The postcss dependency range for nanoid changes to ^3.3.12.

Changes

Dependency lockfile refresh

Layer / File(s) Summary
Refresh nanoid and postcss metadata
package-lock.json
Updates locked versions and integrity metadata for nanoid and postcss, and updates postcss’s nanoid dependency range.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Suggested reviewers: semantic-release-bot, mtrezza, parseplatformorg, dblythy, cbaker6


Caution

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

  • Ignore

❌ Failed checks (2 errors)

Check name Status Explanation Resolution
Description check ❌ Error The description omits the required Issue, Approach, and Tasks sections from the template. Add the missing template sections and briefly fill in the issue, approach, and task checkboxes, even if some items are not applicable.
Engage In Review Feedback ❌ Error Only a single Dependabot lockfile bump exists; I found no reply, discussion, or follow-up commit showing engagement with review feedback. Reply in the review thread first, then either land a commit implementing the feedback or persuade the reviewer to retract it before resolving.
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title matches the required prefix format and clearly describes the dependency bump.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Security Check ✅ Passed Only package-lock metadata changed; postcss is bumped to 8.5.19 and nanoid to 3.3.16, both above published vulnerable ranges.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dependabot/npm_and_yarn/postcss-8.5.14

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mtrezza
mtrezza merged commit f0285a5 into alpha Jul 13, 2026
11 checks passed
@mtrezza
mtrezza deleted the dependabot/npm_and_yarn/postcss-8.5.14 branch July 13, 2026 21:47
@parseplatformorg

Copy link
Copy Markdown
Contributor

🎉 This change has been released in version 9.2.1-alpha.1

@parseplatformorg parseplatformorg added the state:released-alpha Released as alpha version label Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Bot label; pull requests that updates a dependency file javascript Pull requests that update javascript code state:released-alpha Released as alpha version

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants