Skip to content

chore(deps-dev): bump postcss from 8.5.16 to 8.5.26 in /client - #44

Closed
dependabot[bot] wants to merge 524 commits into
devfrom
dependabot/npm_and_yarn/client/postcss-8.5.26
Closed

dependabot[bot] wants to merge 524 commits into
devfrom
dependabot/npm_and_yarn/client/postcss-8.5.26

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 19, 2026

Copy link
Copy Markdown

Bumps postcss from 8.5.16 to 8.5.26.

Release notes

Sourced from postcss's releases.

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).
Changelog

Sourced from postcss's changelog.

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

- CL-H1: screen_capture_stop 与 dispose 结算防抖中悬挂的 pendingStartResolve,消除渲染层 invoke 永久挂起(快速开始→停止、帧超时重启链不再卡死)
- CL-H2: importTable 每行显式按首行列集合取值(缺失补 null),修复 IndexedDB 迁移行间字段不一致时的列错位静默数据损坏
- CL-H3: db:search LIKE 降级路径统一 LIMIT 20,常见词搜索不再同步全表扫描 + 全量 IPC 传输
- CL-H4: rebuildIndex 改为异步分批执行(每批 500 行 + setImmediate 让出事件循环),数万文档重建不再阻塞主进程窗口/托盘/IPC;同步更新 main.ts 与 migration:complete 调用点
- CL-H5: rateCard 增加 isRating 防重入锁(try/finally 保证异常释放),消除双击/触屏误触导致的同一卡片双调度与重复复习记录

验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
…atchdog上限

- CL-M1: ai:stream:start 的 API 路径白名单校验(仅 /api/v1/(ai|multimodal)/ 前缀,拒绝 ?/# 注入),堵住代理访问任意网关端点
- CL-M2: postJsonStream 读取阶段 30s 无数据超时(原仅覆盖建连)+ 所有退出路径 reader.cancel() 释放连接 + 外部 abort 信号检测
- CL-M3: safeHandleBatched 返回真实结果(最后一次调用结算 Promise),microtask 异常 reject 给调用方而非 unhandledRejection
- CL-M4: 屏幕采集缩略图 1920×1080 → 1280×720(extractFrame 目标分辨率),多窗口每帧位图分配降 56%
- CL-M5: db:batch 批量操作条数上限 1000,防止单事务长期持有写锁阻塞全部 db IPC
- CL-M6: columnCache 失效策略——initialize/close/checkpointAndClose 时 clear,运行期 schema 变更不再过滤新列
- CL-M7: MCP Bridge 子进程最小环境白名单(14 个基础变量),不再透传宿主全部环境变量(供应链凭据泄露面)
- CL-M8: displayMedia handler 校验请求 frame 来源(file:// 或 localhost),非应用来源拒绝授权(防静默录屏+系统音频)
- CL-M9: dbFileMigrator 复制前检查目标目录已存在 keban.db 则拒绝(防覆盖旧库);备份名加时间戳并保留最近 5 份
- CL-M10: 帧超时 watchdog 连续重启上限 3 次(收到有效帧清零),耗尽后停止并 toast 提示,消除幽灵采集循环
- CL-M11: callWithLocalFallback 本地探测缓存过期时先刷新再决策,不再静默跳过本地推理

验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
- CL-L1: fs:read-file 禁止读取数据库文件(keban.db*)+ 50MB 大小限制
- CL-L2: ai:set-gateway-url 拒绝自定义端口与路径(CSP connect-src 动态放行的攻击面收窄)
- CL-L3: backup:save 校验 JSON 内容与 100MB 上限
- CL-L4: 自动更新状态机(idle/checking/available/downloading/downloaded/error)——install 仅 downloaded 态、download 仅 available 态,防止任意时机触发退出安装与并发下载
- CL-L5: chatRepository.getMessages limit 钳制 1-200
- CL-L6: preload 专用监听 API(onWindowClosing/onMaximizedChanged/onSyncBeforeQuit)纳入 ALLOWED_EVENT_CHANNELS 校验
- CL-L7: schema ALTER 区分 duplicate column(幂等成功)与其他错误(记日志且不推进 user_version,保留重试机会)
- CL-L8: video_record_stopped 确认事件校验绑定窗口 sender
- CL-L9: ai:stream 活跃流在发起窗口销毁时 abort 清理
- CL-L10: uncaughtException 崩溃恢复——DB checkpoint 落盘后 relaunch,不再带病运行
- CL-L11: saveAIConfigAction 网关地址同步失败抛错 + gatewaySyncError 状态可观测

验证: npm run lint (0 errors) + npm run test (875 passed) + npm run build 全部通过
- SYNC-H1: Push 冲突判定收紧为 client version <= server version——相同版本号不同内容的静默覆盖改为返回冲突(双设备并发编辑不再丢数据;幂等重试由 op.ID 去重覆盖)
- SYNC-H2: WS sync_request 每连接在飞查询上限 2(信号槽),单连接洪泛不再打满数据库连接池(50)拖垮全部用户
- SYNC-M1: Resolve 增加 FOR UPDATE 行锁 + 版本必须大于服务端版本(拒绝版本回退);成功后广播到其他在线设备(实时收敛)
- SYNC-M2: Push 广播条件从 opSeqNoByID 非空改为 accepted 非空——无 ID 操作(fallback ID)落库后同样广播
- SYNC-M3: CRDTPush changeset SHA-256 哈希幂等去重((user_id, changeset_hash) 唯一索引 + 并发兜底),网络重试不再重复落库膨胀
- SYNC-L2: Pull/CRDTPull 的 deviceId 白名单校验(防回环与超长参数)

验证: go build + go vet + go test 全部通过
- ALG-H1: FSRS S0(G) 从 FSRS-4 硬编码常量 [0.4,0.6,2.4,9.0] 改为权重 w[0..3](fsrs-rs 官方语义 S0(G)=w[G-1]);修正误导注释(权重为项目自定义非官方默认、w[6] 为保留位不参与 difficulty 更新、D0 为固定表近似并标注官方公式);同步更新测试断言
- ALG-M1: sm2 easeFactor 缺失/NaN/0 防御(回退 2.5),消除 NaN interval → Invalid Date 无限传播
- ALG-M2: rateCard 中 updateCard 改为 await + try/catch——异步写失败不再 unhandled rejection;review 已落库时继续推进 UI(内存态最新,DB 旧值下次复习覆盖,不丢数据不重复调度)
- ALG-L1: SM-2 历史 interval 反推 stability 的近似性注释说明
- ALG-L2: goldenErrorMultiplier 历史遗留接口注释(实际由 store 层 compressForGoldenError 后处理生效)

验证: lint 0 errors + 875 tests passed + build 成功(FSRS/SM2 44 项算法测试全通过)
- WEB-L1: DownloadCta 版本信息 fetch 增加 5s 超时 + 单次重试;加载中显示加载提示,源站不可达时明确回退 GitHub Release(原实现 DNS 挂起时按钮一直显示兜底值,无法区分加载中与故障)
- SYNC2-H3: pause() 不再置 syncInProgress(该锁由 sync finally 释放),resume 等待加 15s 超时兜底——存储路径切换等流程不再永久挂起
- SYNC2-H1: resolve 成功后 markEntityLogsSynced 清理该实体全部未同步日志——配合服务端版本语义收紧(<=冲突),消除 resolve 后旧日志永久循环冲突
- SYNC2-H2: 冲突对象 localData 携带真实本地数据(最后一条 payload 日志,纯 delete 回退读业务表),localVersion 取最后一条日志版本——修复保留本地提交空对象清空实体数据
- SYNC2-H4: operationLog.synced 写入数值 0/1 与查询 equals(0/1) 类型一致,修复 oplog push 链路静默失效与模式切换丢数据;类型同步改为 0|1

验证: lint 0 errors + 875 tests passed
- SYNC2-L1: oplog pull cursor advances only to last successfully applied
  version, preventing permanent skip of failed operations
- SYNC2-L2: autoSync no longer counts lock/offline states as failures,
  avoiding spurious exponential backoff after network recovery
- SYNC2-L3: getPendingCRDTChanges supports per-table filtering, fixing
  push starvation when multiple tables have pending changes
- SYNC2-L4: offline queue max version read by version instead of
  createdAt to avoid duplicate versions within the same millisecond
- SYNC2-L5: reset per-table CRDT in-memory doc on persistence failure,
  preventing baseline drift and MissingDependencyError
- #1: JWT algorithm now injected via SUPABASE_JWT_ALGORITHM (default
  HS256, aligned with Supabase default signing); placeholder detection
  prevents 'configured' false impression causing whole-site 401
- #2: remove double rollback on streaming rate-limit overrun - the Lua
  script already atomically DECRs, manual rollback let users drain
  their own quotas into negative counts
- #3: error_pattern chain/router defensive validation - missing fields
  from LLM JSON output filtered instead of 500 (ValidationError)
- #4: GLM generate_vision returns actual clamped max_tokens; vision
  chain logs truncation warning when output approaches the limit
- #5: Gemini generate_stream iteration moved into thread pool via
  asyncio.to_thread, unblocking the event loop during streaming
- #6: providers return real input/output token split; fallback cost
  tracking prefers it and falls back to 60/40 estimate instead of
  the misleading 50/50 split (output priced 2-3x higher)
- #7: balance queries use Key pool primary key (plural env vars),
  DeepSeek balance no longer silently skipped
- #8: JWKS fetch distinguishes network failures (stale cache reuse
  with 60s retry backoff) from HTTP/key errors (fail-closed),
  preventing whole-site 401 on transient Supabase hiccups
- #9: import_concept registered in TIMEOUT_CONFIG/RATE_LIMITS plus
  startup validation warning for unregistered features
- #10: error_pattern cache key includes user_id and hashes full
  content, preventing cross-user result reuse
- #11: vision confidence redefined as structured-extraction
  completeness (text 0.5 + aux fields 0.5) instead of fabricated
  0.9/0.3; GLM ASR fabricated 0.9 fixed to 0.0 placeholder
- #12: fallback chain budget comments unified to *3.0 matching
  implementation (was *1.5, misleading maintainers)
- #13: key rotation moved to with_retry_and_timeout wrapper so
  vision/stream/ASR/video paths rotate keys too, not just generate
- #14: JWT_SECRET marked as dead config in .env/.env.example with
  SUPABASE_JWT_ALGORITHM documented; startup warning when legacy
  JWT_SECRET is set but SUPABASE_JWT_SECRET is empty
- M1: feynman setExplanation no longer auto-advances step (double
  advance skipped step2 view); progression owned by advanceStep
- M2: pomodoro wall-clock calibration completion branch now plays
  sounds and sends notifications like the normal path
- M3: coral streak/check-in/progress use local dates consistently
  (UTC+8 midnight planting was counted as previous day)
- M4: plantCoral re-reads DB before set, no longer overwrites
  concurrent plant with stale snapshot
- M5: CryptoManager init failure now explicit (hasInitFailed, throws);
  device key material encrypted via Electron safeStorage IPC
  (previously plaintext in localStorage); fix missing logger import
  in SyncEngine (phase 1 regression)
- M6: useAudioPlayer.play clears running fadeOut interval
- M7: convertWeakPointsToFlashcards batches card creation before
  marking mastered, avoiding duplicate cards on retry
- M8: useVoiceInput serializes stop/start (pending flag + re-check),
  old stop can no longer kill a newly started capture
- ELEC2-M1: MCP manager init failure resets initialized flag and
  retries with exponential backoff (1s-30s, max 8 attempts) - the
  stale flag previously disabled MCP silently for the whole run
- ELEC2-L1: window recreation (macOS activate) resets sync-before-quit
  state machine - stale requested=true + completed=false made the new
  window impossible to close
- ELEC2-L2: audio capture runtime degradation re-checks capturing
  before restarting the provider, eliminating ghost capture when
  stop() races with degradeToEndpoint
High:
- OfflineQueue: orderBy('version') on non-indexed field throws Dexie
  SchemaError, breaking offline enqueue (regression from SYNC2-L4);
  switched to sortBy in-memory (enqueue/getPendingItems/getReadyItems)
- auth.py JWKS: network-failure branch now bounded by stale-grace
  window (was unbounded stale reuse); in-lock retry_after reuse
  added; 5xx treated as transient (stale reuse) vs 4xx fail-closed

Medium:
- error_pattern: cache-hit path now validates/filters like first-run
  (was bypassing validation -> 500); cache stores cleaned data;
  negative count/empty keywords filtered
- Key rotation: removed per-provider generate rotate (double rotation
  with wrapper made even-key pools never use the 2nd key)
- writeWithLog: resetTable failure no longer propagates to block the
  main write path
- SyncEngine: finally clears syncInProgress unconditionally (pause
  during in-flight sync left the lock, resume waited 15s timeout)
- feynmanStepSlice: catch path now syncs zustand store so retry does
  not duplicate cards for already-created weak points
- windowManager: window recreation clears syncTimeoutTimer (stale
  timer would app.quit() the rebuilt window)
- rate_limit: global-limit overrun now rolls back the feature counter
  (Lua only rolls back the exceeded layer)

Low:
- markEntityLogsSynced matches synced !== 1 (legacy boolean/undefined)
- parseLocalDate validates format; daysBetween NaN -> Infinity
- ecosystem initialize uses local date; restore() re-reads DB
- worldState streak diff uses Math.round tolerance
- useVoiceInput start timeout surfaces error message
- Gemini stream uses provider thread pool (not default executor)
- qwen_vision returns max_tokens for truncation detection
- jwt_algorithm normalized strip().upper()
- X1: CryptoManager.init now wired to auth lifecycle (login derives
  device key via safeStorage, logout clears; init failure surfaces
  explicit warning toast instead of silent plaintext); mcpManager
  gains shuttingDown flag - no retry scheduling after shutdown and
  retryAttempts reset for dev hot-reload
- X2: electron.d.ts duplicate Window.electronAPI declaration removed
  (env.d.ts is the single authoritative superset; conflicting
  signatures were masked by skipLibCheck)
- X4: Gemini vision/multi/video return real input/output token split
  for cost tracking; DeepSeek input tokens use cache-miss portion
  (cache-hit billed at 1/4 price, previously overestimated)
- X5: error_pattern cache key uses only fields the chain consumes
  (first 20 correctAnswer/userAnswer, no flashcardId) - improves
  hit rate without correctness impact
- X6: feature-config startup validation extracted to shared function
  and applied to streaming registry (was middleware-only, streaming
  misconfigs silently fell back to 300s timeout / default limits)
- 收入方案设计:docs/product/temporary-revenue-implementation.md
- 数据库层:schema.ts 新增 beta_profile/licenses/invite_codes 三表,SCHEMA_VERSION=10
- 类型系统:client/src/types/beta.ts — UserTier/TIER_RANK/TIER_PERKS 权益矩阵
- 状态管理:betaStore.ts — Zustand persist 持久化 tier/激活码/邀请码
- UI组件:BetaProfile(身份卡片)、InviteCodeSection(邀请码管理)、
  LicenseActivation(激活码输入+服务端验证)、UpgradePrompt(非阻断升级引导)
- 权限Hook:useTierAccess(tier-based 功能访问控制)、useBetaProfile(metadata加载)
- SettingsPage 集成:ProfileSettings 后插入 BetaProfile 区域
- AI网关集成:rate_limit.py TIER_LIMITS 分级配额 + providers.py TIER_MODEL_ACCESS 分级路由
- 新增路由:routers/license.py(激活码验证) + routers/beta.py(邀请码API)
- 管理工具:scripts/license-gen.mjs(激活码离线生成,支持 PRO/LIFE/SND1/THM1)
- 代码审查修复:修复 recalcEffectiveTier 排序、激活码大小写、tier 参数传递、
  服务端验证缺失、v10迁移、邀请码数量逻辑、cohort 类型转换、import re 延迟导入等30个问题
- 路由注册:main.py 和 __init__.py 注册 license_router 和 beta_router
Aparencia and others added 21 commits August 16, 2026 23:39
- 预置 ~/.bubblewrap/config.json(jdkPath/androidSdkPath),消除全新 runner
  上 JDK 安装交互提示导致的 exit 130(v0.38~v0.40 build-apk 连续失败根因)
- 删除语义错误的 bubblewrap update(--manifest 应指向本地 twa-manifest.json
  而非 web manifest URL);工程已入库,直接 build 即可
- build 密码改经 BUBBLEWRAP_KEYSTORE_PASSWORD/BUBBLEWRAP_KEY_PASSWORD
  环境变量传入(CLI 无密码参数,原 --keystorePass 等被静默忽略)
- 签名参数改用 --signingKeyPath/--signingKeyAlias(原 --keystorePath 无效,
  会落到 twa-manifest.json 中的 Windows 本地路径)
- 防御:SDK tools/bin 占位 + build-tools 36.1.0 缺失时显式预装
- keystore secret 缺失时 exit 1 显式失败;GitHub Release 上传仅 tag 触发时执行

已在本地完成全链路构建验证(gradle assembleRelease + zipalign + apksigner,
产出 2.6MB 签名 APK 验证通过)
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.16 to 8.5.26.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.16...8.5.26)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.26
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 19, 2026
@Aparencia Aparencia closed this Aug 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/client/postcss-8.5.26 branch August 21, 2026 03:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant