-
Notifications
You must be signed in to change notification settings - Fork 77
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update postcss #122
Comments
Second this. Dependabot alerts are triggering me :) |
For the life of me I can't even imagine why it would take 2 months to review a pull request. 🤦🏻 |
Judging from pull requests and commits acctivity It appears that project is no longer mainained. |
Hey! I've created PR updating PostCSS usage. Give it a thumbs up - maybe that will give it some traction 🤷 |
There's already a pull request open. That's the point, it's been open since December. |
OH ... it's yours that's open. Yeah I saw that one, hence my original comment. |
FYI, it looks like the Dependabot alert was updated, and this is no longer a security issue. The updated status shows that it's fixed in |
As the SFC compiler for Vue 2.7 now uses PostCSS 8, it make sense to update it. |
This issue is back from the dead - https://nvd.nist.gov/vuln/detail/CVE-2023-44270
|
Please consider updating postcss to a version >= 8.2.13 since versions below are affected by Regular Expression Denial of Service.
See GHSA-566m-qj78-rww5 for more information.
The text was updated successfully, but these errors were encountered: