Skip to content

deps: Bump postcss to 8.5.10#44

Merged
wu21-web merged 2 commits into
mainfrom
bump-postcss
May 22, 2026
Merged

deps: Bump postcss to 8.5.10#44
wu21-web merged 2 commits into
mainfrom
bump-postcss

Conversation

@wu21-web

Copy link
Copy Markdown
Owner

PostCSS has XSS via Unescaped </style> in its CSS Stringify Output

@vercel

vercel Bot commented May 22, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
me-reader Ready Ready Preview, Comment May 22, 2026 4:41am

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a version override for postcss in package.json, pinning it to version 8.5.10. The review feedback highlights that this results in a downgrade from version 8.5.15 and suggests using a caret range (^8.5.10) instead of a fixed version to allow for patch updates and more efficient dependency hoisting.

Comment thread package.json Outdated
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@wu21-web wu21-web merged commit 19b818f into main May 22, 2026
9 checks passed
@wu21-web wu21-web deleted the bump-postcss branch May 22, 2026 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant