Skip to content

Bump dependencies for security alerts - #1368

Merged
ecraig12345 merged 4 commits into
mainfrom
dependabot/npm_and_yarn/postcss-8.5.24
Aug 5, 2026
Merged

Bump dependencies for security alerts#1368
ecraig12345 merged 4 commits into
mainfrom
dependabot/npm_and_yarn/postcss-8.5.24

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.19 to 8.5.24.

Release notes

Sourced from postcss's releases.

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

Changelog

Sourced from postcss's changelog.

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 5, 2026
Copilot AI balanced review requested due to automatic review settings August 5, 2026 04:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 5, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI review requested due to automatic review settings August 5, 2026 05:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 3 changed files in this pull request and generated no new comments.

Suppressed comments (1)

.github/dependabot.yml:1

  • This removes the repository's only Dependabot update configuration, which is unrelated to the PostCSS bump and is not mentioned in the PR description. Please restore the file so this dependency-only PR does not silently remove the repository's explicit npm update policy.

Copilot AI review requested due to automatic review settings August 5, 2026 05:19
@ecraig12345 ecraig12345 changed the title Bump postcss from 8.5.19 to 8.5.24 Bump dependencies for security alerts Aug 5, 2026
dependabot Bot and others added 3 commits August 4, 2026 22:20
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.19 to 8.5.24.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.19...8.5.24)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.24
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@ecraig12345
ecraig12345 force-pushed the dependabot/npm_and_yarn/postcss-8.5.24 branch from 3ca496b to 5233864 Compare August 5, 2026 05:20
@ecraig12345
ecraig12345 enabled auto-merge (squash) August 5, 2026 05:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated no new comments.

Copilot AI review requested due to automatic review settings August 5, 2026 05:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 2 out of 6 changed files in this pull request and generated no new comments.

Suppressed comments (1)

change/@microsoft-beachball-action-should-release-4f682097-4f7b-4a44-8fa9-c87006f0dfa5.json:3

  • This change entry indicates the PR is about updating the undici dependency, but the PR also deletes .github/dependabot.yml (disabling Dependabot updates). If the Dependabot removal is intentional, it should be documented in the PR/change notes as a separate rationale; otherwise, consider reverting that deletion to keep the PR focused on the dependency bump.
  "comment": "Update undici dependency",

@ecraig12345
ecraig12345 merged commit a98080c into main Aug 5, 2026
12 checks passed
@ecraig12345
ecraig12345 deleted the dependabot/npm_and_yarn/postcss-8.5.24 branch August 5, 2026 05:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants