Skip to content

security: pin postcss-selector-parser to 7.1.6 - #663

Merged
tbantle22 merged 1 commit into
mainfrom
taylor/sec-postcss-selector-parser
Oct 6, 2026
Merged

tbantle22 merged 1 commit into
mainfrom
taylor/sec-postcss-selector-parser

Conversation

@tbantle22

Copy link
Copy Markdown
Collaborator

Clears Dependabot #159 (medium, quadratic complexity in flat selector parsing).

cssnano's postcss-calc pulled a 6.x copy of postcss-selector-parser alongside the 7.x one the @csstools plugins already use. Pinning the 6.x ranges collapses everything onto the single patched 7.1.6.

yarn ci passes — the plugins that consume it run during stylelint and the postcss build step.

The other two alerts have no fix

Both report no patched version upstream, so there's nothing to bump to:

Both are build/test-only transitives and neither is bundled into the published packages, which externalize only dependencies and peerDependencies. Forcing js-yaml to 4 would break load-nyc-config, which calls the safeLoad that v4 removed. Suggest dismissing both until upstream patches land.

🤖 Generated with Claude Code

cssnano's postcss-calc pulled a 6.x copy alongside the 7.x one the
@csstools plugins use. Everything now resolves to the single patched
release.

The other two open alerts have no upstream fix: http-cache-semantics
(via node-gyp, from fsevents and @parcel/watcher) and sprintf-js (via
js-yaml 3 and argparse 1, from jest's coverage config loader) both
report no patched version. Neither ships in the published packages.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@tbantle22
tbantle22 merged commit 24b25c6 into main Oct 6, 2026
1 check passed
@tbantle22
tbantle22 deleted the taylor/sec-postcss-selector-parser branch October 6, 2026 21:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant