Skip to content

Bump postcss from 8.5.18 to 8.5.23 in /tooling/tailwind - #301

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18
Closed

Bump postcss from 8.5.18 to 8.5.23 in /tooling/tailwind#301
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 28, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.18 to 8.5.23.

Release notes

Sourced from postcss's releases.

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).
Changelog

Sourced from postcss's changelog.

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 28, 2026
@dependabot
dependabot Bot requested a review from aamoghS as a code owner July 28, 2026 03:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 28, 2026
@github-actions

Copy link
Copy Markdown
Contributor

@dependabot merge

@github-actions

github-actions Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/postcss 8.5.23 🟢 7.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Code-Review🟢 3Found 9/30 approved changesets -- score normalized to 3
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • tooling/tailwind/package.json

@dependabot dependabot Bot changed the title Bump postcss from 8.5.14 to 8.5.18 in /tooling/tailwind Bump postcss from 8.5.18 to 8.5.23 in /tooling/tailwind Aug 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18 branch from fe469bc to 1d918f9 Compare August 3, 2026 22:19
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@dependabot merge

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.18 to 8.5.23.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.18...8.5.23)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.18
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18 branch from 1d918f9 to e43e2fd Compare August 5, 2026 03:36
@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@dependabot merge

@aamoghS
aamoghS force-pushed the dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18 branch from e43e2fd to 9d570cc Compare August 10, 2026 18:04
@github-actions

github-actions Bot commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Visit the preview URL for this PR (updated for commit c69cee9):

https://hacklytics2027--pr-301-avh3iqwl.web.app

(expires Mon, 17 Aug 2026 18:27:02 GMT)

🔥 via Firebase Hosting GitHub Action 🌎

Sign: c48ba34db61581e25fe2978355160b5eefe0e83f

@aamoghS
aamoghS force-pushed the dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18 branch from 9d570cc to c69cee9 Compare August 10, 2026 18:21
@aamoghS aamoghS closed this Aug 10, 2026
@aamoghS
aamoghS deleted the dependabot/npm_and_yarn/tooling/tailwind/postcss-8.5.18 branch August 10, 2026 20:42
@dependabot @github

dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant