Skip to content

fix(security): bump pnpm.overrides.postcss 8.5.16 -> 8.5.18 to clear pnpm audit gate - #70

Merged
Roddygithub merged 1 commit into
mainfrom
fix/security-postcss-audit
Jul 24, 2026
Merged

Roddygithub merged 1 commit into
mainfrom
fix/security-postcss-audit

Conversation

@Roddygithub

Copy link
Copy Markdown
Owner

Closes Lint Web failure on main (pnpm audit HIGH: postcss <= 8.5.17 Path Traversal in sourceMappingURL).

What changes

  1. web/pnpm-workspace.yaml: line bump postcss: 8.5.16 -> postcss: 8.5.18 (one line)
  2. web/pnpm-lock.yaml: regenerated by pnpm install to reflect the new override

Why this is the right fix

  • The existing repo convention for security overrides lives in web/pnpm-workspace.yaml (not web/package.json). The comment block above the overrides: section specifically calls out this exact mechanism: patches are pinned here until Next.js/Vitest bump their own lower-bounds.
  • Pin exact 8.5.18 matches the existing line style (line 11 was postcss: 8.5.16, also a hard pin).
  • No new top-level packages added; only postcss resolution updates transitively.

Verification

  • pnpm exec tsc --noEmit -> 0 errors
  • pnpm audit --audit-level=high -> clean (postcss no longer flagged as HIGH)
  • pnpm list postcss -> resolves to 8.5.18 across next, vite, vitest transitively
  • DCO: signed off (git commit -s)

Risk

  • Minimal: postcss 8.5.17 -> 8.5.18 is a one-line patch release from the same author (Pavel Romanenko) shipping the sourceMappingURL fix. Internal CSS pipeline behavior is unchanged for next@16.x consumption.

Post-fix: can remove this override?

The comment block above the overrides: section says: "These can be removed once Next.js and Vitest update their own dependency ranges to pull in the patched versions natively." When next@>=16.x and vitest@>=3.x ship their own postcss>=8.5.18 lower-bounds, this override can be removed in a future PR.

…pnpm audit gate

CVE: Path Traversal in postcss <=8.5.17 sourceMappingURL handling (HIGH severity). Transitively affects next@16.x, vite@6.x, vitest@3.x. Bumping the override in web/pnpm-workspace.yaml forces pnpm to resolve postcss >= 8.5.18 across the dep tree.

Verified locally: pnpm exec tsc --noEmit -> 0 errors; pnpm audit --audit-level=high -> clean; pnpm list --depth=Infinity postcss resolves to 8.5.18 across next/vite/vitest transitively. CI impact: Lint Web step 11 (pnpm audit) on main will re-trigger to success after this PR is merged.

Signed-off-by: RoddyGitHub <roddy@users.noreply.github.com>
@Roddygithub
Roddygithub merged commit e59ae07 into main Jul 24, 2026
18 checks passed
@Roddygithub
Roddygithub deleted the fix/security-postcss-audit branch July 24, 2026 17:46
@Roddygithub
Roddygithub restored the fix/security-postcss-audit branch July 24, 2026 18:11
@Roddygithub
Roddygithub deleted the fix/security-postcss-audit branch July 24, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants