Skip to content

security: bump postcss past path-traversal advisory (GHSA-r28c-9q8g-f849, high) #650

Description

@schmug

Task

Bump postcss from 8.5.15 to >8.5.17 to fix GHSA-r28c-9q8g-f849 (high) — a path-traversal issue where postcss auto-loads an external .map file referenced by an untrusted sourceMappingURL comment, allowing arbitrary file disclosure.

Pointers

package-lock.json → node_modules/postcss (transitive dependency — run npm ls postcss to confirm the parent(s) pulling it in).

Constraints

Scope to this one dependency. If no direct manifest entry exists, an overrides entry in package.json pinning postcss to >8.5.17 is the safe path. Run npm run typecheck, npm run lint, and npm test and keep green.

Acceptance

npm audit no longer reports GHSA-r28c-9q8g-f849; full test/lint/typecheck suite green.

Out of scope

hono advisory (tracked separately, see companion issue). brace-expansion and the wrangler/miniflare/sharp chain are already covered by open Dependabot PRs #648 and #635 — do not duplicate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    securitySecurity hardening or vulnerability

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions