Skip to content

Commit 4b69b90

Browse files
chore: upgrade postcss to ^8.5.15 to address CVE-2026-41305
Refreshed the lockfile so transitive postcss instances resolve to 8.5.15. next@16.2.6 hard-pins postcss at 8.4.31, so a qualified resolution keyed to that exact range redirects it to ^8.5.10 (resolves to 8.5.15). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 4c9dfe0 commit 4b69b90

3 files changed

Lines changed: 12 additions & 32 deletions

File tree

CHANGELOG.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
99

1010
### Fixed
1111
- Upgraded `protobufjs` to `^7.6.2`. [#1281](https://github.com/sourcebot-dev/sourcebot/pull/1281)
12+
- Upgraded `postcss` to `^8.5.15`. [#PR](https://github.com/sourcebot-dev/sourcebot/pull/PR)
1213

1314
## [5.0.1] - 2026-06-04
1415

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@
4040
"sucrase/glob": "^10.5.0",
4141
"rimraf@npm:5.0.10/glob": "^10.5.0",
4242
"@opentelemetry/resources": "2.5.1",
43+
"postcss@npm:8.4.31": "^8.5.10",
4344
"path-to-regexp@0.1.12": "0.1.13",
4445
"path-to-regexp@^8": "^8.4.0",
4546
"picomatch@^4": "^4.0.4",

yarn.lock

Lines changed: 10 additions & 32 deletions
Original file line numberDiff line numberDiff line change
@@ -17933,12 +17933,12 @@ __metadata:
1793317933
languageName: node
1793417934
linkType: hard
1793517935

17936-
"nanoid@npm:^3.3.11, nanoid@npm:^3.3.6":
17937-
version: 3.3.11
17938-
resolution: "nanoid@npm:3.3.11"
17936+
"nanoid@npm:^3.3.12":
17937+
version: 3.3.12
17938+
resolution: "nanoid@npm:3.3.12"
1793917939
bin:
1794017940
nanoid: bin/nanoid.cjs
17941-
checksum: 10c0/40e7f70b3d15f725ca072dfc4f74e81fcf1fbb02e491cf58ac0c79093adc9b0a73b152bcde57df4b79cd097e13023d7504acb38404a4da7bc1cd8e887b82fe0b
17941+
checksum: 10c0/ba142b7b39e11e80c16dd74b0365d407880c87c1cf7e1480956981ae940ee36060fa5b6f092cd1e315184dd19244c657bd017d03327bd3c62247d691c5e8edfb
1794217942
languageName: node
1794317943
linkType: hard
1794417944

@@ -19147,36 +19147,14 @@ __metadata:
1914719147
languageName: node
1914819148
linkType: hard
1914919149

19150-
"postcss@npm:8.4.31":
19151-
version: 8.4.31
19152-
resolution: "postcss@npm:8.4.31"
19150+
"postcss@npm:^8.4.47, postcss@npm:^8.5.10, postcss@npm:^8.5.8":
19151+
version: 8.5.15
19152+
resolution: "postcss@npm:8.5.15"
1915319153
dependencies:
19154-
nanoid: "npm:^3.3.6"
19155-
picocolors: "npm:^1.0.0"
19156-
source-map-js: "npm:^1.0.2"
19157-
checksum: 10c0/748b82e6e5fc34034dcf2ae88ea3d11fd09f69b6c50ecdd3b4a875cfc7cdca435c958b211e2cb52355422ab6fccb7d8f2f2923161d7a1b281029e4a913d59acf
19158-
languageName: node
19159-
linkType: hard
19160-
19161-
"postcss@npm:^8.4.47, postcss@npm:^8.5.10":
19162-
version: 8.5.12
19163-
resolution: "postcss@npm:8.5.12"
19164-
dependencies:
19165-
nanoid: "npm:^3.3.11"
19166-
picocolors: "npm:^1.1.1"
19167-
source-map-js: "npm:^1.2.1"
19168-
checksum: 10c0/5baebaf574c567bc1b3d61197f38af4ce5920b8f611c887fb6bc3dcc14af00253c169dbf19897bc889cce0b0d9818ab5eb4ea0caedf02b0bab10da8a43ce8c12
19169-
languageName: node
19170-
linkType: hard
19171-
19172-
"postcss@npm:^8.5.8":
19173-
version: 8.5.9
19174-
resolution: "postcss@npm:8.5.9"
19175-
dependencies:
19176-
nanoid: "npm:^3.3.11"
19154+
nanoid: "npm:^3.3.12"
1917719155
picocolors: "npm:^1.1.1"
1917819156
source-map-js: "npm:^1.2.1"
19179-
checksum: 10c0/7cb2b32202ea1ead03f15cfbb2756a64a0f98942378e99b3dfce33678fe5eaf93e31d675a46e3a0dfb417d7b49b82d8999d0dd42a33c3b128e71ade0f978719a
19157+
checksum: 10c0/7f2e63ae22fbe43aace1bf652bd99da4e90737c64194d49e51ddc9cd0f9e51ff2861a7d734379b494deffa03a880a5c65eec70bc29ee9ebaa7136dde3eee8f31
1918019158
languageName: node
1918119159
linkType: hard
1918219160

@@ -21386,7 +21364,7 @@ __metadata:
2138621364
languageName: node
2138721365
linkType: hard
2138821366

21389-
"source-map-js@npm:^1.0.2, source-map-js@npm:^1.2.1":
21367+
"source-map-js@npm:^1.2.1":
2139021368
version: 1.2.1
2139121369
resolution: "source-map-js@npm:1.2.1"
2139221370
checksum: 10c0/7bda1fc4c197e3c6ff17de1b8b2c20e60af81b63a52cb32ec5a5d67a20a7d42651e2cb34ebe93833c5a2a084377e17455854fee3e21e7925c64a51b6a52b0faf

0 commit comments

Comments
 (0)