Alert
Dependabot alert #1 — security/dependabot/1, surfaced by the CodeQL check summary on #62.
| Field |
Value |
| Package |
postcss (npm) |
| Vulnerable range |
< 8.5.10 |
| First patched |
8.5.10 |
| Severity |
medium (CVSS 6.1) |
| Advisory |
GHSA-qx2v-qp2m-jg93 / CVE-2026-41305 |
| CWE |
CWE-79 (XSS) |
Where it comes from
pnpm why postcss shows two copies; only the runtime one is vulnerable:
postcss@8.4.31 ← vulnerable
└─ next@16.2.4 → website (dependencies)
postcss@8.5.13 ← already patched, ignore
└─ @tailwindcss/postcss@4.2.4 → website (devDependencies)
The vulnerable instance is a transitive dep of next, not in package.json.
Practical exploitability for this site
The advisory requires user-submitted CSS to be parsed and re-stringified. This site is a static-export marketing page (output: "export", see AGENTS.md); postcss only runs at build time over our own source files. Exploit prerequisites are not present, so impact is informational — the alert still needs to clear from the security tab.
Fix options
- Wait for a Next.js bump that pulls postcss >= 8.5.10 transitively. Cheapest. Check at the next minor release.
- pnpm override in
package.json (recommended explicit fix — dedupes both copies and silences the alert):
"pnpm": {
"overrides": {
"postcss": ">=8.5.10"
}
}
Then pnpm install and re-run pnpm build to verify nothing breaks.
pnpm update postcss — works only if pnpm's resolver picks the new version under next's constraint.
Acceptance
Alert
Dependabot alert #1 — security/dependabot/1, surfaced by the CodeQL check summary on #62.
postcss(npm)< 8.5.108.5.10Where it comes from
pnpm why postcssshows two copies; only the runtime one is vulnerable:The vulnerable instance is a transitive dep of
next, not inpackage.json.Practical exploitability for this site
The advisory requires user-submitted CSS to be parsed and re-stringified. This site is a static-export marketing page (
output: "export", see AGENTS.md); postcss only runs at build time over our own source files. Exploit prerequisites are not present, so impact is informational — the alert still needs to clear from the security tab.Fix options
package.json(recommended explicit fix — dedupes both copies and silences the alert):pnpm installand re-runpnpm buildto verify nothing breaks.pnpm update postcss— works only if pnpm's resolver picks the new version under next's constraint.Acceptance
pnpm buildsucceedspnpm why postcssreports a single copy >= 8.5.10 (or both copies on patched versions)