Skip to content

fix(deps): bump postcss to >=8.5.23 (XSS fix, closes #663) - #687

Merged
birme merged 1 commit into
mainfrom
security/663-postcss-update
Sep 17, 2026
Merged

birme merged 1 commit into
mainfrom
security/663-postcss-update

Conversation

@birme

@birme birme commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Adds overrides: { postcss: ">=8.5.23" } in package.json to force vite's transitive postcss to a safe version
  • Before: postcss@8.5.6 (vulnerable); After: postcss@8.5.28 (safe)
  • Fixes GHSA-qx2v-qp2m-jg93 (XSS via unescaped </style>), GHSA-6g55-p6wh-862q and related sourceMappingURL path traversal CVEs

Test plan

  • npm run build passes
  • npm test passes
  • npm run lint passes

Closes #663

Resolves GHSA-qx2v-qp2m-jg93 and related sourceMappingURL path traversal
issues in postcss <=8.5.22. Uses npm overrides to force vite's transitive
dependency to a safe version.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@birme

birme commented Sep 17, 2026

Copy link
Copy Markdown
Contributor Author

Code Review

Verdict: LGTM

Summary: Forces vite's transitive postcss to >=8.5.23 (resolves 8.5.28), fixing the </style> XSS (#663). Shares overrides with #681 — reconcile on merge.

Reviewed against the Open Intercom code-reviewer rubric (TypeScript correctness, error handling, architecture, testing, security, WebRTC/SDP, npm-migration hygiene). No Blocking items; CI green. Approving and squash-merging via daily-backlog-pr Phase 3.

@birme
birme merged commit 59cc3ce into main Sep 17, 2026
6 checks passed
@birme
birme deleted the security/663-postcss-update branch September 17, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: postcss <=8.5.17 XSS via unescaped </style> in CSS stringify output

2 participants