Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(v4): remove is-svg dependency #1036

Merged
merged 1 commit into from Apr 6, 2021
Merged

fix(v4): remove is-svg dependency #1036

merged 1 commit into from Apr 6, 2021

Conversation

AviVahl
Copy link

@AviVahl AviVahl commented Apr 3, 2021

backport of #1034 to the v4 branch.

closes #1030

@AviVahl
Copy link
Author

AviVahl commented Apr 3, 2021

The yarn.lock changes were generated by executing latest yarn@1 on latest node@10 (in the root of repo).
Tests pass locally.

@AviVahl
Copy link
Author

AviVahl commented Apr 3, 2021

Tested locally on Node v6.17.1 as well. Tests pass.

Copy link
Member

@alexander-akait alexander-akait left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Collaborator

@ludofischer ludofischer left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, I am not familiar with the PostCSS 7 API but since the tests pass I think there can't be a mistake at that level.

packages/postcss-svgo/src/__tests__/index.js Outdated Show resolved Hide resolved
backport of #1034 to the v4 branch
@alexander-akait alexander-akait merged commit 83985ca into cssnano:v4 Apr 6, 2021
@AviVahl AviVahl deleted the v4 branch April 6, 2021 12:11
@AviVahl AviVahl restored the v4 branch April 6, 2021 12:12
@ludofischer ludofischer linked an issue Apr 6, 2021 that may be closed by this pull request
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2021-28092 in cssnano due to an old version of is-svg
3 participants