Skip to content

Update dependency cssnano to v4.1.1 #43

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dev-mend-for-github-com[bot]
Copy link

@dev-mend-for-github-com dev-mend-for-github-com bot commented Jan 12, 2025

This PR contains the following updates:

Package Type Update Change
cssnano dependencies patch 4.1.0 -> 4.1.1

By merging this PR, the issue #24 will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability
High High 8.1 WS-2019-0063
High High 7.5 WS-2019-0032
High High 7.5 WS-2021-0152
High High 7.3 CVE-2020-8116
Medium Medium 5.3 CVE-2021-23364
Medium Medium 5.3 CVE-2021-23382
Medium Medium 5.3 CVE-2021-29060

Release Notes

cssnano/cssnano (cssnano)

v4.1.1

Compare Source

4.1.1 - 2018-09-25

Bug Fixes

  • css-declaration-sorter was removed from default prevent.
  • postcss-normalize-timing-functions doesn't lowercased property anymore.
  • postcss-normalize-positons now handles uppercase properties.
  • postcss-normalize-url now is case-insensitive.
  • postcss-merge-idents now is case-insensitive.
  • postcss-merge-rules now is case-insensitive.
  • postcss-minify-selectors now is case-insensitive.
  • postcss-minify-font-values now is case-insensitive.
  • postcss-normalize-unicode now has correct dependencies.
  • postcss-minify-params now has correct dependencies.

Other changes

  • cssnano-preset-advanced use Autoprefixer 9.
  • use PostCSS 7 in all plugins.

  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by Mend label Jan 12, 2025
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 7 times, most recently from b2026db to a6f0f18 Compare January 20, 2025 19:46
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 6 times, most recently from 93c9e65 to f6ab503 Compare January 29, 2025 09:16
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 5 times, most recently from 1cd20ef to d13499d Compare February 5, 2025 11:59
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 9 times, most recently from 6db309d to 08e86f7 Compare February 13, 2025 03:28
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 2 times, most recently from ce18277 to d829bcf Compare February 14, 2025 08:26
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 8 times, most recently from 8ab2425 to 5026f25 Compare May 1, 2025 06:20
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 5 times, most recently from f982cb8 to 3791142 Compare May 8, 2025 03:38
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 5 times, most recently from c98bc2b to 5fa2e2f Compare May 15, 2025 19:02
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 7 times, most recently from 2eae545 to c09e6c0 Compare May 29, 2025 03:37
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch 3 times, most recently from 512c1b0 to 75b9b4c Compare June 4, 2025 11:11
@dev-mend-for-github-com dev-mend-for-github-com bot force-pushed the whitesource-remediate/cssnano-4.x-lockfile branch from 75b9b4c to eec4aef Compare June 4, 2025 14:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants