Skip to content

fix(deps): override PostCSS to patched version (GHSA-qx2v-qp2m-jg93)#37

Merged
gregnazario merged 1 commit into
mainfrom
cursor/postcss-security-override-3b48
May 15, 2026
Merged

fix(deps): override PostCSS to patched version (GHSA-qx2v-qp2m-jg93)#37
gregnazario merged 1 commit into
mainfrom
cursor/postcss-security-override-3b48

Conversation

@gregnazario

Copy link
Copy Markdown
Contributor

Summary

Adds a pnpm.overrides entry for postcss so the transitive chain vitestvitepostcss resolves to 8.5.10 or newer, addressing the moderate XSS advisory (GHSA-qx2v-qp2m-jg93) affecting postcss < 8.5.10.

Verification

  • pnpm audit — no known vulnerabilities
  • pnpm test — all 106 tests passed
  • pnpm run check — Biome clean

The lockfile now pins postcss@8.5.14.

Open in Web Open in Cursor 

Add pnpm override postcss>=8.5.10 so transitive vite dependency no longer pulls vulnerable 8.5.8.

Co-authored-by: Greg Nazario <greg@gnazar.io>
@gregnazario gregnazario marked this pull request as ready for review May 15, 2026 17:20
@gregnazario gregnazario merged commit 10859ce into main May 15, 2026
18 checks passed
@gregnazario gregnazario deleted the cursor/postcss-security-override-3b48 branch May 15, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants