Task
Bump postcss from 8.5.15 to >8.5.17 to fix GHSA-r28c-9q8g-f849 (high) — a path-traversal issue where postcss auto-loads an external .map file referenced by an untrusted sourceMappingURL comment, allowing arbitrary file disclosure.
Pointers
package-lock.json → node_modules/postcss (transitive dependency — run npm ls postcss to confirm the parent(s) pulling it in).
Constraints
Scope to this one dependency. If no direct manifest entry exists, an overrides entry in package.json pinning postcss to >8.5.17 is the safe path. Run npm run typecheck, npm run lint, and npm test and keep green.
Acceptance
npm audit no longer reports GHSA-r28c-9q8g-f849; full test/lint/typecheck suite green.
Out of scope
hono advisory (tracked separately, see companion issue). brace-expansion and the wrangler/miniflare/sharp chain are already covered by open Dependabot PRs #648 and #635 — do not duplicate.
Task
Bump
postcssfrom 8.5.15 to >8.5.17 to fix GHSA-r28c-9q8g-f849 (high) — a path-traversal issue where postcss auto-loads an external.mapfile referenced by an untrustedsourceMappingURLcomment, allowing arbitrary file disclosure.Pointers
package-lock.json→node_modules/postcss(transitive dependency — runnpm ls postcssto confirm the parent(s) pulling it in).Constraints
Scope to this one dependency. If no direct manifest entry exists, an
overridesentry inpackage.jsonpinningpostcssto>8.5.17is the safe path. Runnpm run typecheck,npm run lint, andnpm testand keep green.Acceptance
npm auditno longer reports GHSA-r28c-9q8g-f849; full test/lint/typecheck suite green.Out of scope
honoadvisory (tracked separately, see companion issue).brace-expansionand the wrangler/miniflare/sharp chain are already covered by open Dependabot PRs #648 and #635 — do not duplicate.