Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update postcss #44

Closed
sotten opened this issue May 19, 2021 · 4 comments
Closed

update postcss #44

sotten opened this issue May 19, 2021 · 4 comments

Comments

@sotten
Copy link

sotten commented May 19, 2021

Please Update postcss/postcss to the newest version (8.2.15).
postcss/postcss#1567

@andyjansson
Copy link
Owner

andyjansson commented May 19, 2021

We don't actually include postcss as a dependency, so there's nothing for us to update here. postcss is listed as a peer dependency, meaning that the plugin will work for any version you pair it with, as long as it's within the same semver range (which happens to be 8.0.0 and up).

Also, how does the PR relate to your request?

@sotten
Copy link
Author

sotten commented May 19, 2021

The PR Fixed a Regular Expression Denial of Service. See https://www.npmjs.com/advisories/1693
and https://nvd.nist.gov/vuln/detail/CVE-2021-23382

If I understand it correctly, package-lock.json sets the dependency to a fixed version. The dependabot has also changed the dependency as in #43.

@andyjansson
Copy link
Owner

You seem to be under a misapprehension of how package-lock.json works. Whatever version we have set in our repository does not apply to you as a consumer; You have your own package-lock.json that dictate what version will be installed.

@sotten
Copy link
Author

sotten commented May 19, 2021

Learned something again. Sorry for the issue and thanks for the explanation.

@sotten sotten closed this as completed May 19, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants