Bump postcss, postcss-focus, postcss-loader, postcss-reporter and postcss-simple-vars - #84
Bump postcss, postcss-focus, postcss-loader, postcss-reporter and postcss-simple-vars#84dependabot[bot] wants to merge 1 commit into
Conversation
…tcss-simple-vars Bumps [postcss](https://github.com/postcss/postcss) to 8.5.26 and updates ancestor dependencies [postcss](https://github.com/postcss/postcss), [postcss-focus](https://github.com/postcss/postcss-focus), [postcss-loader](https://github.com/webpack/postcss-loader), [postcss-reporter](https://github.com/postcss/postcss-reporter) and [postcss-simple-vars](https://github.com/postcss/postcss-simple-vars). These dependencies need to be updated together. Updates `postcss` from 5.2.18 to 8.5.26 - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/postcss/postcss/commits/8.5.26) Updates `postcss-focus` from 1.0.0 to 7.0.0 - [Release notes](https://github.com/postcss/postcss-focus/releases) - [Changelog](https://github.com/postcss/postcss-focus/blob/main/CHANGELOG.md) - [Commits](postcss/postcss-focus@1.0.0...7.0.0) Updates `postcss-loader` from 3.0.0 to 8.2.1 - [Release notes](https://github.com/webpack/postcss-loader/releases) - [Changelog](https://github.com/webpack/postcss-loader/blob/main/CHANGELOG.md) - [Commits](webpack/postcss-loader@v3.0.0...v8.2.1) Updates `postcss-reporter` from 1.4.1 to 7.1.0 - [Changelog](https://github.com/postcss/postcss-reporter/blob/main/CHANGELOG.md) - [Commits](postcss/postcss-reporter@1.4.1...7.1.0) Updates `postcss-simple-vars` from 3.1.0 to 7.0.1 - [Changelog](https://github.com/postcss/postcss-simple-vars/blob/main/CHANGELOG.md) - [Commits](postcss/postcss-simple-vars@3.1.0...7.0.1) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.26 dependency-type: indirect - dependency-name: postcss-focus dependency-version: 7.0.0 dependency-type: direct:production - dependency-name: postcss-loader dependency-version: 8.2.1 dependency-type: direct:production - dependency-name: postcss-reporter dependency-version: 7.1.0 dependency-type: direct:production - dependency-name: postcss-simple-vars dependency-version: 7.0.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
| } | ||
| }, | ||
| "@babel/runtime": { | ||
| "node_modules/@babel/runtime": { |
There was a problem hiding this comment.
Medium severity vulnerability introduced by a package you're using:
Line 1208 lists a dependency (@babel/runtime) with a known Medium severity vulnerability. Fixing requires upgrading or replacing the dependency.
ℹ️ Why this matters
Affected versions of @babel/helpers, @babel/runtime, @babel/runtime-corejs2, and @babel/runtime-corejs3 are vulnerable to Inefficient Regular Expression Complexity. Babel generates a polyfill (the wrapRegExp helper) for String.prototype.replace on regular expressions with named capturing groups that has quadratic (ReDoS) complexity when an untrusted replacement string containing the substring $< is processed. The vulnerable code is generated polyfill code rather than a symbol you call directly, so any project transpiling named capturing groups against affected browser targets is at risk. Upgrade to a patched version and recompile your code to remediate.
To resolve this comment:
Upgrade this dependency to at least version 7.26.10 at package-lock.json.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "@babel/helper-function-name": "^7.1.0", | ||
| "@babel/template": "^7.1.0", | ||
| "@babel/traverse": "^7.1.0", | ||
| "@babel/types": "^7.2.0" | ||
| } | ||
| }, | ||
| "@babel/helpers": { | ||
| "node_modules/@babel/helpers": { |
There was a problem hiding this comment.
Medium severity vulnerability introduced by a package you're using:
Line 373 lists a dependency (@babel/helpers) with a known Medium severity vulnerability. Fixing requires upgrading or replacing the dependency.
ℹ️ Why this matters
Affected versions of @babel/helpers, @babel/runtime, @babel/runtime-corejs2, and @babel/runtime-corejs3 are vulnerable to Inefficient Regular Expression Complexity. Babel generates a polyfill (the wrapRegExp helper) for String.prototype.replace on regular expressions with named capturing groups that has quadratic (ReDoS) complexity when an untrusted replacement string containing the substring $< is processed. The vulnerable code is generated polyfill code rather than a symbol you call directly, so any project transpiling named capturing groups against affected browser targets is at risk. Upgrade to a patched version and recompile your code to remediate.
To resolve this comment:
Upgrade this dependency to at least version 7.26.10 at package-lock.json.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "version": "1.1.1", | ||
| "resolved": "https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz", | ||
| "integrity": "sha1-WQxhFWsK4vTwJVcyoViyZrxWsh0=" | ||
| }, | ||
| "ejs": { | ||
| "node_modules/ejs": { |
There was a problem hiding this comment.
Medium severity vulnerability may affect your project—review required:
Line 3651 lists a dependency (ejs) with a known Medium severity vulnerability.
ℹ️ Why this matters
Affected versions of ejs are vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') / Protection Mechanism Failure. ejs before 3.1.10 lacks prototype-pollution protection when handling template options, so a polluted Object.prototype can inject options such as client and escapeFunction into the template compiler and reach arbitrary-code paths. Any code that compiles or renders a template through render, renderFile, compile, or the Template constructor exercises the vulnerable options handling.
To resolve this comment:
Check if you are using ejs on the CLI.
- If you're affected, upgrade this dependency to at least version 3.1.10 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "pako": "~1.0.5" | ||
| } | ||
| }, | ||
| "browserslist": { | ||
| "node_modules/browserslist": { |
There was a problem hiding this comment.
Medium severity vulnerability may affect your project—review required:
Line 2393 lists a dependency (browserslist) with a known Medium severity vulnerability.
ℹ️ Why this matters
Affected versions of browserslist are vulnerable to Inefficient Regular Expression Complexity / Uncontrolled Resource Consumption. Calling the browserslist() query parser on a crafted query string triggers catastrophic regular-expression backtracking (ReDoS), allowing an attacker to consume excessive CPU and deny service.
To resolve this comment:
Check if you are using browserslist on the CLI.
- If you're affected, upgrade this dependency to at least version 4.16.5 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "resolved": "https://registry.npmjs.org/js-tokens/-/js-tokens-3.0.2.tgz", | ||
| "integrity": "sha1-mGbfOVECEw449/mWvOtlRDIJwls=" | ||
| }, | ||
| "node_modules/js-yaml": { |
There was a problem hiding this comment.
Medium severity vulnerability may affect your project—review required:
Line 6415 lists a dependency (js-yaml) with a known Medium severity vulnerability.
ℹ️ Why this matters
Affected versions of js-yaml are vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'). js-yaml is vulnerable to prototype pollution through its YAML merge key (<<) handling. When parsing untrusted YAML with load, loadAll, safeLoad, or safeLoadAll, a crafted document containing a __proto__ key inside a merged mapping can modify the prototype of the resulting object, leading to integrity violations in the application.
To resolve this comment:
Check if you are using js-yaml on the CLI.
- If you're affected, upgrade this dependency to at least version 3.14.2 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "nanotiming": "^7.2.0", | ||
| "remove-array-items": "^1.0.0" | ||
| "node_modules/ripemd160": { | ||
| "version": "2.0.2", |
There was a problem hiding this comment.
Medium severity vulnerability may affect your project—review required:
Line 11208 lists a dependency (webpack-dev-server) with a known Medium severity vulnerability.
ℹ️ Why this matters
Affected versions of webpack-dev-server are vulnerable to Exposed Dangerous Method or Function. webpack-dev-server serves bundled assets without rejecting cross-origin classic script requests. Because such <script src> requests bypass the same-origin policy, a malicious website visited by a developer running the dev server can load the application bundle cross-origin and, via prototype pollution of the webpack runtime, extract the application source code.
To resolve this comment:
Check if you are using webpack dev server CLI setup.
- If you're affected, upgrade this dependency to at least version 5.2.1 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "nanotiming": "^7.2.0", | ||
| "remove-array-items": "^1.0.0" | ||
| "node_modules/ripemd160": { | ||
| "version": "2.0.2", |
There was a problem hiding this comment.
Medium severity vulnerability may affect your project—review required:
Line 11208 lists a dependency (webpack-dev-server) with a known Medium severity vulnerability.
ℹ️ Why this matters
Affected versions of webpack-dev-server are vulnerable to Origin Validation Error. webpack-dev-server improperly validates the WebSocket connection Origin header, unconditionally accepting any IP-address-based Origin. A malicious website can perform a cross-site WebSocket hijack against a running dev server and exfiltrate the developer source code carried in Hot Module Reloading (HMR) messages. The insecure origin check is the package default and is reached on every WebSocket connection, so any project running an affected version is vulnerable.
To resolve this comment:
Check if you are using webpack dev server CLI setup and access untrusted web site with non-Chromium based browser.
- If you're affected, upgrade this dependency to at least version 5.2.1 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "resolved": "https://registry.npmjs.org/js-tokens/-/js-tokens-3.0.2.tgz", | ||
| "integrity": "sha1-mGbfOVECEw449/mWvOtlRDIJwls=" | ||
| }, | ||
| "node_modules/js-yaml": { |
There was a problem hiding this comment.
High severity vulnerability may affect your project—review required:
Line 6415 lists a dependency (js-yaml) with a known High severity vulnerability.
ℹ️ Why this matters
Affected versions of js-yaml are vulnerable to Inefficient Algorithmic Complexity / Uncontrolled Resource Consumption. An attacker can supply a YAML document containing a chain of mappings that each merge the previous one via the merge key (<<), causing js-yaml to spend quadratic CPU time while parsing input whose size grows only linearly, resulting in a denial of service.
To resolve this comment:
Check if you are using js-yaml on the CLI.
- If you're affected, upgrade this dependency to at least version 3.15.0 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "nanotiming": "^7.2.0", | ||
| "remove-array-items": "^1.0.0" | ||
| "node_modules/ripemd160": { | ||
| "version": "2.0.2", |
There was a problem hiding this comment.
High severity vulnerability introduced by a package you're using:
Line 9932 lists a dependency (terser) with a known High severity vulnerability. Fixing requires upgrading or replacing the dependency.
ℹ️ Why this matters
terser versions before 4.8.1, >= 5.0.0 before 5.14.2 are vulnerable to Inefficient Regular Expression Complexity.
To resolve this comment:
Upgrade this dependency to at least version 4.8.1 at package-lock.json.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| }, | ||
| "is-fullwidth-code-point": { | ||
| "node_modules/get-func-name": { |
There was a problem hiding this comment.
High severity vulnerability introduced by a package you're using:
Line 5201 lists a dependency (get-func-name) with a known High severity vulnerability. Fixing requires upgrading or replacing the dependency.
ℹ️ Why this matters
Affected version of get-func-name is vulnerable to Uncontrolled Resource Consumption / Inefficient Regular Expression Complexity. The current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks.
To resolve this comment:
Upgrade this dependency to at least version 2.0.1 at package-lock.json.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "resolved": "https://registry.npmjs.org/regenerator-runtime/-/regenerator-runtime-0.13.2.tgz", | ||
| "integrity": "sha512-S/TQAZJO+D3m9xeN1WTI8dLKBBiRgXBlTJvbWjCThHWZj9EvHK70Ff50/tYj2J/fvBY6JtFVwRuazHN2E7M9BA==" | ||
| }, | ||
| "node_modules/@babel/preset-env": { |
There was a problem hiding this comment.
Critical severity vulnerability may affect your project—review required:
Line 1094 lists a dependency (@babel/preset-env) with a known Critical severity vulnerability.
ℹ️ Why this matters
Affected versions of @babel/traverse and babel-traverse are vulnerable to Incomplete List of Disallowed Inputs / Incorrect Comparison. Compiling untrusted code with Babel using plugins that invoke the internal path.evaluate() or path.evaluateTruthy() methods (for example @babel/plugin-transform-runtime, @babel/preset-env with useBuiltIns, or any polyfill‐provider plugin) allows a maliciously crafted AST to execute arbitrary code on the build machine during compilation.
To resolve this comment:
Check if you use Babel to compile untrusted JavaScript.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| } | ||
| }, | ||
| "@babel/plugin-transform-runtime": { | ||
| "node_modules/@babel/plugin-transform-runtime": { |
There was a problem hiding this comment.
Critical severity vulnerability may affect your project—review required:
Line 968 lists a dependency (@babel/plugin-transform-runtime) with a known Critical severity vulnerability.
ℹ️ Why this matters
Affected versions of @babel/traverse and babel-traverse are vulnerable to Incomplete List of Disallowed Inputs / Incorrect Comparison. Compiling untrusted code with Babel using plugins that invoke the internal path.evaluate() or path.evaluateTruthy() methods (for example @babel/plugin-transform-runtime, @babel/preset-env with useBuiltIns, or any polyfill‐provider plugin) allows a maliciously crafted AST to execute arbitrary code on the build machine during compilation.
To resolve this comment:
Check if you use Babel to compile untrusted JavaScript.
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
| "@babel/code-frame": "^7.0.0", | ||
| "@babel/parser": "^7.4.0", | ||
| "@babel/types": "^7.4.0" | ||
| } | ||
| }, | ||
| "@babel/traverse": { | ||
| "node_modules/@babel/traverse": { |
There was a problem hiding this comment.
Critical severity vulnerability may affect your project—review required:
Line 1231 lists a dependency (@babel/traverse) with a known Critical severity vulnerability.
ℹ️ Why this matters
Affected versions of @babel/traverse and babel-traverse are vulnerable to Incomplete List of Disallowed Inputs / Incorrect Comparison. Compiling untrusted code with Babel using plugins that invoke the internal path.evaluate() or path.evaluateTruthy() methods (for example @babel/plugin-transform-runtime, @babel/preset-env with useBuiltIns, or any polyfill‐provider plugin) allows a maliciously crafted AST to execute arbitrary code on the build machine during compilation.
To resolve this comment:
Check if you use Babel to compile untrusted JavaScript.
- If you're affected, upgrade this dependency to at least version 7.23.2 at package-lock.json.
- If you're not affected, comment
/fp we don't use this [condition]
💬 Ignore this finding
To ignore this, reply with:
/fp <comment>for false positive/ar <comment>for acceptable risk/other <comment>for all other reasons
You can view more details on this finding in the Semgrep AppSec Platform here.
Bumps postcss to 8.5.26 and updates ancestor dependencies postcss, postcss-focus, postcss-loader, postcss-reporter and postcss-simple-vars. These dependencies need to be updated together.
Updates
postcssfrom 5.2.18 to 8.5.26Release notes
Sourced from postcss's releases.
... (truncated)
Changelog
Sourced from postcss's changelog.
... (truncated)
Commits
Maintainer changes
This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.
Updates
postcss-focusfrom 1.0.0 to 7.0.0Changelog
Sourced from postcss-focus's changelog.
Commits
03285f3Release 7.0 version30dbdd7Clean up codecb807a9Clean up testsb65ebd3Fix package description9a99568Run tests in parallel2655382Update dependencies9740d22Remove old Node.js support70ca20eMove to pnpm 84cc660fMove to Node.js 20cc4da18Lock pnpm on CIUpdates
postcss-loaderfrom 3.0.0 to 8.2.1Release notes
Sourced from postcss-loader's releases.
... (truncated)
Changelog
Sourced from postcss-loader's changelog.
... (truncated)
Commits
583677echore(release): 8.2.1a3ed7e2fix: update peer dependency for@rspack/corev2 (#717)c984ff4test: fix (#715)cc01d2bci: fixd4faa34docs: update contributingb1e4fa5chore: correct link (#713)d990168chore: migration to main org and branch (#712)522a07dchore(release): 8.2.09c74974feat: updatejitifrom v1 to v25a781e5chore: update github actions/checkout from v4 to v5 (#709)Maintainer changes
This version was pushed to npm by evilebottnawi, a new releaser for postcss-loader since your current version.
Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Updates
postcss-reporterfrom 1.4.1 to 7.1.0Changelog
Sourced from postcss-reporter's changelog.
... (truncated)
Commits
4145438Prepare 7.1.00abeb49Update funding in package.json978feeeUpdate dependencies7109853Should also report errors by default (#75)af4f833Fix job name and update action02b3f38Update CI48566aeBump postcss from 8.4.5 to 8.4.31 (#74)c533483Fix Node.js 12 CI support0f9cd79Add funding option100813cPrepare 7.0.5Maintainer changes
This version was pushed to npm by ai, a new releaser for postcss-reporter since your current version.
Updates
postcss-simple-varsfrom 3.1.0 to 7.0.1Changelog
Sourced from postcss-simple-vars's changelog.
... (truncated)
Commits
f9b9661Release 7.0.1 versione71464fUpdate dependenciesea9b351Add Node.js 19 to CI4e51a4bmake parameter &variablesproperty optional. (#120)1126e31Release 7.0 version505b5ffClean up code9c6e25eUpdate dev practices65ca9ec117: Support backslash sequences and unicode transformation (#118)aaa29b9Bump jsdom from 16.4.0 to 16.7.0 (#116)4fce22bBump semver-regex from 3.1.3 to 3.1.4 (#115)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.