Skip to content

fix: resolve GHSA-fxqj-rqcc-2cmp in postcss - #698

Open
benoitf wants to merge 1 commit into
redhat-developer:mainfrom
benoitf:cve-fix/ghsa-fxqj-rqcc-2cmp-main
Open

fix: resolve GHSA-fxqj-rqcc-2cmp in postcss#698
benoitf wants to merge 1 commit into
redhat-developer:mainfrom
benoitf:cve-fix/ghsa-fxqj-rqcc-2cmp-main

Conversation

@benoitf

@benoitf benoitf commented Sep 4, 2026

Copy link
Copy Markdown
Collaborator

What does this PR do?

Fix moderate severity vulnerability GHSA-fxqj-rqcc-2cmp in postcss.

Advisory: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset
Vulnerable versions: <=8.5.22
Patched versions: >=8.5.23
Advisory URL: GHSA-fxqj-rqcc-2cmp

Screenshot / video of UI

N/A - dependency update only.

What issues does this PR fix or reference?

Fixes GHSA-fxqj-rqcc-2cmp: PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappingURL reads arbitrary .map files when from is unset

How to test this PR?

Run pnpm audit and verify GHSA-fxqj-rqcc-2cmp is no longer reported

Upgrade postcss to satisfy >=8.5.23
Advisory: GHSA-fxqj-rqcc-2cmp

Co-authored-by: Claude <noreply@anthropic.com>
Signed-off-by: Florent Benoit <fbenoit@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant