From 0162fbce2cec52ef04d9440073b7e3e6efb1af54 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 9 Oct 2026 06:07:05 +0000 Subject: [PATCH 1/4] chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /playground Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] --- playground/package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/playground/package-lock.json b/playground/package-lock.json index 8ee5cb9..9bc69af 100644 --- a/playground/package-lock.json +++ b/playground/package-lock.json @@ -1010,9 +1010,9 @@ } }, "node_modules/source-map-js": { - "version": "1.2.1", - "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", - "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "version": "1.2.2", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.2.tgz", + "integrity": "sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==", "dev": true, "license": "BSD-3-Clause", "engines": { From 056aabb00b494b8d49fd6a5cf378306dddbf57a3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 9 Oct 2026 06:29:08 +0000 Subject: [PATCH 2/4] chore(deps): bump source-map-js from 1.2.1 to 1.2.2 in /playground Bumps [source-map-js](https://github.com/7rulnik/source-map-js) from 1.2.1 to 1.2.2. - [Release notes](https://github.com/7rulnik/source-map-js/releases) - [Changelog](https://github.com/7rulnik/source-map-js/blob/main/CHANGELOG.md) - [Commits](https://github.com/7rulnik/source-map-js/compare/v1.2.1...v1.2.2) --- updated-dependencies: - dependency-name: source-map-js dependency-version: 1.2.2 dependency-type: indirect ... Signed-off-by: dependabot[bot] --- playground/package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/playground/package-lock.json b/playground/package-lock.json index bdee3d1..fbd4bac 100644 --- a/playground/package-lock.json +++ b/playground/package-lock.json @@ -1010,9 +1010,9 @@ } }, "node_modules/source-map-js": { - "version": "1.2.1", - "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.1.tgz", - "integrity": "sha512-UXWMKhLOwVKb728IUtQPXxfYU+usdybtUrK/8uGE8CQMvrhOpwvzDBwj0QhSL7MQc7vIsISBG8VQ8+IDQxpfQA==", + "version": "1.2.2", + "resolved": "https://registry.npmjs.org/source-map-js/-/source-map-js-1.2.2.tgz", + "integrity": "sha512-KGj/8Y43x35aZVDtt+J4mK1hoLGHULMYfSkODJNQjNDC3oW1PqPoxMwo0pLUsWM/UEGzON/NxeHywEfNXNP3Vw==", "dev": true, "license": "BSD-3-Clause", "engines": { From aefd53696e3b291291db181fb39b760311583ae6 Mon Sep 17 00:00:00 2001 From: Nikolai Denissov Date: Fri, 9 Oct 2026 09:32:25 +0300 Subject: [PATCH 3/4] Test chained CSS source maps and invalid indexed offsets --- .../tests/dependencies/source-maps.test.mjs | 47 +++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 playground/tests/dependencies/source-maps.test.mjs diff --git a/playground/tests/dependencies/source-maps.test.mjs b/playground/tests/dependencies/source-maps.test.mjs new file mode 100644 index 0000000..99c94ee --- /dev/null +++ b/playground/tests/dependencies/source-maps.test.mjs @@ -0,0 +1,47 @@ +import assert from "node:assert/strict"; +import { test } from "node:test"; +import { createRequire } from "node:module"; +import postcss from "postcss"; + +// Resolve the same consumer PostCSS uses, including if npm nests the dependency. +const require = createRequire(import.meta.resolve("postcss")); +const { SourceMapConsumer } = require("source-map-js"); + +test("chained CSS transforms retain original locations and Unicode source content", async () => { + const input = '.course::before {\n content: "Näytä 📚";\n margin: 0;\n}\n'; + const first = await postcss([{ + postcssPlugin: "rename-course-selector", + Rule(rule) { rule.selector = ".course-material::before"; }, + }]).process(input, { from: "course.css", to: "intermediate.css", map: { inline: false } }); + const second = await postcss([{ + postcssPlugin: "expand-course-spacing", + Declaration(decl) { if (decl.prop === "margin") decl.value = "1rem"; }, + }]).process(first.css, { + from: "intermediate.css", to: "built.css", + map: { inline: false, prev: first.map.toJSON() }, + }); + assert.match(second.css, /\.course-material::before/); + assert.match(second.css, /margin: 1rem/); + const lines = second.css.split("\n"); + const line = lines.findIndex((text) => text.includes("margin:")); + const consumer = new SourceMapConsumer(second.map.toJSON()); + const original = consumer.originalPositionFor({ line: line + 1, column: lines[line].indexOf("margin:") }); + assert.match(original.source, /(^|\/)course\.css$/); + assert.equal(original.line, 3); + assert.equal(original.column, 2); + assert.equal(consumer.sourceContentFor(original.source), input); +}); + +// 1.2.2 rejects invalid indexed offsets before they can expand into huge maps. +// Only construct the consumer: never attempt the expensive vulnerable expansion. +test("indexed source maps reject invalid section offsets before processing", () => { + for (const line of [10_000_001, -1, 1.5, Infinity]) { + assert.throws(() => new SourceMapConsumer({ + version: 3, + sections: [{ + offset: { line, column: 0 }, + map: { version: 3, sources: ["course.css"], names: [], mappings: "AAAA" }, + }], + }), /offset/i); + } +}); From 10462baf5836b9587c391f54f19df97f65a5dd46 Mon Sep 17 00:00:00 2001 From: Nikolai Denissov Date: Fri, 9 Oct 2026 09:36:40 +0300 Subject: [PATCH 4/4] Refresh Nix dependencies after source-map-js update --- playground.nix | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/playground.nix b/playground.nix index 775566d..caa1877 100644 --- a/playground.nix +++ b/playground.nix @@ -11,7 +11,7 @@ pkgs.buildNpmPackage { src = ./playground; - npmDepsHash = "sha256-dUqllE2sz39VuF1++jNSdahM4uOeU87GFJe6OLnnV5A="; + npmDepsHash = "sha256-6iUjz6heVP5CNlRHA6eFPUr6BvONuzNlIY+mfpf4FP0="; nativeBuildInputs = [ pkgs.wasm-bindgen-cli