[Snyk] Upgrade: , , , , cosmiconfig, css-functions-list, debug, micromatch, fast-glob, ignore, known-css-properties, picocolors, postcss, postcss-resolve-nested-selector, postcss-selector-parser, supports-hyperlinks, table #62
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯♂ The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
@csstools/css-parser-algorithms
from 2.3.0 to 2.7.1 | 10 versions ahead of your current version | 2 months ago
on 2024-07-06
@csstools/css-tokenizer
from 2.1.1 to 2.4.1 | 11 versions ahead of your current version | 2 months ago
on 2024-07-05
@csstools/media-query-list-parser
from 2.1.2 to 2.1.13 | 11 versions ahead of your current version | 2 months ago
on 2024-07-06
@csstools/selector-specificity
from 3.0.0 to 3.1.1 | 5 versions ahead of your current version | 4 months ago
on 2024-05-13
cosmiconfig
from 8.2.0 to 8.3.6 | 7 versions ahead of your current version | a year ago
on 2023-09-13
css-functions-list
from 3.1.0 to 3.2.2 | 3 versions ahead of your current version | 5 months ago
on 2024-04-22
debug
from 4.3.4 to 4.3.6 | 2 versions ahead of your current version | 2 months ago
on 2024-07-27
micromatch
from 4.0.5 to 4.0.8 | 3 versions ahead of your current version | 21 days ago
on 2024-08-23
fast-glob
from 3.3.0 to 3.3.2 | 2 versions ahead of your current version | 10 months ago
on 2023-11-06
ignore
from 5.2.4 to 5.3.2 | 3 versions ahead of your current version | a month ago
on 2024-08-12
known-css-properties
from 0.28.0 to 0.34.0 | 6 versions ahead of your current version | 3 months ago
on 2024-06-18
picocolors
from 1.0.0 to 1.0.1 | 1 version ahead of your current version | 4 months ago
on 2024-05-14
postcss
from 8.4.24 to 8.4.41 | 17 versions ahead of your current version | a month ago
on 2024-08-05
postcss-resolve-nested-selector
from 0.1.1 to 0.1.6 | 4 versions ahead of your current version | a month ago
on 2024-08-12
postcss-selector-parser
from 6.0.13 to 6.1.2 | 6 versions ahead of your current version | a month ago
on 2024-08-12
supports-hyperlinks
from 3.0.0 to 3.1.0 | 1 version ahead of your current version | 24 days ago
on 2024-08-20
table
from 6.8.1 to 6.8.2 | 1 version ahead of your current version | 6 months ago
on 2024-03-26
Issues fixed by the recommended upgrade:
SNYK-JS-BRACES-6838727
SNYK-JS-MICROMATCH-6838728
SNYK-JS-POSTCSS-5926692
Release notes
Package name: @csstools/css-parser-algorithms
-
2.7.1 - 2024-07-06
-
2.7.0 - 2024-06-29
-
2.6.3 - 2024-05-04
-
2.6.2 - 2024-05-04
-
2.6.1 - 2024-03-13
-
2.6.0 - 2024-02-19
-
2.5.0 - 2023-12-31
-
2.4.0 - 2023-12-15
-
2.3.2 - 2023-09-24
-
2.3.1 - 2023-07-24
-
2.3.0 - 2023-07-03
from @csstools/css-parser-algorithms GitHub release notesPackage name: @csstools/css-tokenizer
-
2.4.1 - 2024-07-05
-
2.4.0 - 2024-07-05
-
2.3.3 - 2024-07-03
-
2.3.2 - 2024-06-29
-
2.3.1 - 2024-05-04
-
2.3.0 - 2024-05-04
-
2.2.4 - 2024-03-13
-
2.2.3 - 2023-12-31
-
2.2.2 - 2023-12-15
-
2.2.1 - 2023-09-24
-
2.2.0 - 2023-07-24
-
2.1.1 - 2023-04-10
from @csstools/css-tokenizer GitHub release notesPackage name: @csstools/media-query-list-parser
-
2.1.13 - 2024-07-06
-
2.1.12 - 2024-06-29
-
2.1.11 - 2024-05-04
-
2.1.10 - 2024-05-04
-
2.1.9 - 2024-03-13
-
2.1.8 - 2024-02-19
-
2.1.7 - 2023-12-31
-
2.1.6 - 2023-12-15
-
2.1.5 - 2023-09-24
-
2.1.4 - 2023-08-05
-
2.1.3 - 2023-07-24
-
2.1.2 - 2023-07-03
from @csstools/media-query-list-parser GitHub release notesPackage name: @csstools/selector-specificity
-
3.1.1 - 2024-05-13
-
3.1.0 - 2024-05-11
-
3.0.3 - 2024-03-31
-
3.0.2 - 2024-02-19
-
3.0.1 - 2023-12-15
-
3.0.0 - 2023-07-03
from @csstools/selector-specificity GitHub release notesPackage name: cosmiconfig
-
8.3.6 - 2023-09-13
- ignore search place if accessing it causes ENOTDIR (i.e. if access of a subpath of a file is attempted) (5bd915a)
-
8.3.5 - 2023-09-08
- pass null to transform function for backwards compat (2b38510)
-
8.3.4 - 2023-09-04
- remove node: prefix from imports (f76484a), closes #323
-
8.3.3 - 2023-09-03
- add back node 14 compat (7392541), closes #320
-
8.3.2 - 2023-09-02
- use
- use default for async TS loader (5bed3e3)
-
8.3.1 - 2023-09-02
- do not resolve
-
8.3.0 - 2023-09-02
- add support for TypeScript configuration files (d88b1b4)
-
8.2.0 - 2023-06-04
from cosmiconfig GitHub release notes8.3.6 (2023-09-13)
Bug Fixes
8.3.5 (2023-09-08)
Bug Fixes
8.3.4 (2023-09-04)
Bug Fixes
8.3.3 (2023-09-03)
Bug Fixes
8.3.2 (2023-09-02)
Bug Fixes
.cjsextension for sync compiled typescript (0d76a9a)8.3.1 (2023-09-02)
Bug Fixes
stopDirwhen undefined (59082e2), closes #3178.3.0 (2023-09-02)
Features
8.2.0
Package name: css-functions-list
-
3.2.2 - 2024-04-22
- Add additional function references
-
3.2.1 - 2023-10-15
- Add additional function references
-
3.2.0 - 2023-07-10
- Update with latest function definitions
- Keep functions that end with
-
3.1.0 - 2022-06-03
- Add OKLCH and OKLab functions
from css-functions-list GitHub release notesChanged
Changed
X|Y|Z, likerotatexorrotatey(rotateXor
rotateY) (#4)Added
(#4)
Package name: debug
-
4.3.6 - 2024-07-27
- Avoid using deprecated RegExp.$1 by @ bluwy in #969
- @ bluwy made their first contribution in #969
-
4.3.5 - 2024-05-31
- cac39b1 Fix/debug depth (#926)
-
4.3.4 - 2022-03-17
- Add section about configuring JS console to show debug messages by @ gitname in #866
- Replace deprecated String.prototype.substr() by @ CommanderRoot in #876
- @ gitname made their first contribution in #866
- @ CommanderRoot made their first contribution in #876
from debug GitHub release notesWhat's Changed
New Contributors
Full Changelog: 4.3.5...4.3.6
Patch
Thank you @ calvintwr for the fix.
What's Changed
New Contributors
Full Changelog: 4.3.3...4.3.4
Package name: micromatch
-
4.0.8 - 2024-08-23
-
4.0.7 - 2024-05-22
-
4.0.6 - 2024-05-21
-
4.0.5 - 2022-03-24
from micromatch GitHub release notesUltimate release that fixes both CVE-2024-4067 and CVE-2024-4068. We consider the issues low-priority, so even if you see automated scanners saying otherwise, don't be scared.
No content.
Resolves #249
… thanks to @ joyceerhl at Microsoft.
See #233 for more details.
Package name: fast-glob
-
3.3.2 - 2023-11-06
- Handle square brackets as a special character on Windows in escape functions (#425)
- Keep escaping after brace expansion (#422)
-
3.3.1 - 2023-07-22
-
3.3.0 - 2023-06-30
- In the past, we mishandled patterns that contained slashes when the
- Several problems with matching patterns that contain brace expansion have been resolved. The primary issue solved is when the pattern has duplicate slashes after it is expanded (#394), or the
- All negative patterns will now have the
- The issue that led to duplicates in the results when overlapping or duplicate patterns were present among the patterns has been fixed. At the moment, we are only talking about leading dot. Other cases are not included. For example, running with the patterns
- The benchmark in CI is now running on Node.js 20.
- The benchmark now uses the public package bencho instead of an in-house implementation. You may want to try this solution for your packages and provide feedback.
- @ josh-hemphill made their first contribution in #383
- @ mairaw made their first contribution in #401
from fast-glob GitHub release notes🐛 Bug fixes
This release fixes a regression for cases where the
ignoreoption is used with a string (#403, #404).The public interface of this package does not support a string as the value for the
ignoreoption since 2018 year (release).So, in the next major release, we will reintroduce method implementations that do not involve strings in the
ignoreoption.🚀 Improvements
Method aliases
New methods (
glob,globSync,globStream) have been added in addition to the current methods (default import,sync,stream), which eliminate the need to rename the method when importing. In addition, anasyncalias has been added for the default import, which makes it possible to use this packet with ESM.Method to convert paths to globs
A new method (
convertPathToPattern) has been added in this release to convert a path to a pattern. The primary goal is to enable users to avoid processing Windows paths in each location where this package is used by utilities from third-party packages.See more details in the pull request.
🐛 Bug fixes
baseNameMatchoption was enabled, which went against the documented behavior. (#312)micromatchpackage does not correctly generate a regular expression (#365).dotoption enabled when matching paths. Previously, the!**/*patterns did not exclude hidden files (start with a dot). (#343)['./file.md', 'file.md', '*']will now only includefile.mdonce in the results. (#190)📖 Documentation
A clarifying note has been added for the
concurrencyoption, which provides more detailed information about the Thread Pool utilization.⚙️ Infrastructure
🥇 New Contributors
Package name: ignore
-
5.3.2 - 2024-08-12
-
5.3.1 - 2024-02-01
-
5.3.0 - 2023-11-16
- MINOR export
-
5.2.4 - 2022-12-19
- PATCH fixes normal single asterisk and normal consecutive asterisks defined in gitignore spec (#57)
- PATCH invalid trailing backslash will not throw unexpectedly
from ignore GitHub release notes5.3.2: fixes #130, fixes consequent escaped backslashes
5.3.1: #108: remove BOM before processing .gitignore rules
5.3.0
Optionsinterface (#105)An upgrade is safe for all dependents
It allows typing external methods which expect
Optionsas a param, by importing theOptionsinterface.An upgrade is recommended for all dependents
The following rules could be not properly parsed with previous
ignoreversionsPackage name: known-css-properties
-
0.34.0 - 2024-06-18
- add missing properties by @ Mouvedia in #174
- @ Mouvedia made their first contribution in #174
-
0.33.0 - 2024-06-17
- Safari 17.3
- Chrome 126
- Chrome 126 android
- Firefox 127
- Firefox 120 android
-
0.32.0 - 2024-06-13
- Chrome 125
- Chrome 125 android
- Firefox 126
- Firefox 126 android
- ios safari 17.5
- w3c 2024/06/13
-
0.31.0 - 2024-05-09
- Chrome 123
- Chrome 124
- Chrome android 124
- Firefox 123
- Firefox 124
- Firefox 125
- Firefox android 125
- Samsung internet 25.0
- ios safari 17.4
- w3c 2024/05/09
-
0.30.0 - 2024-03-07
- Chrome 119
- Firefox 119
- Chrome 120
- Firefox 120
- Chrome 121
- Firefox 121
- Chrome 122
- Firefox 122
- Samsung internet 23.0
- ios safari 17.3
- Safari 17.1
- w3c 2024/02/07
-
0.29.0 - 2023-10-15
- Safari 16.5
- Safari 17.0
- ios safari 17.0
- Chrome 116
- Chrome 117
- Chrome android 117
- Chrome 118
- Firefox 114
- Firefox 116
- Firefox 117
- Firefox 118
- Firefox android 118
- W3C data 2023/10/15
- Update dependency globby to v13.2.2 by @ renovate in #158
- Update dependency eslint to v8.51.0 by @ renovate in #155
-
0.28.0 - 2023-07-20
- Chrome 111
- Chrome 112
- Chrome 113
- Chrome 114
- Chrome 114
- Chrome 115
- Firefox 111
- Firefox 112
- Firefox 113
- Firefox 115
- Chrome android 113
- Chrome android 114
- Firefox mobile 115
- Safari 16.4
- Samsung internet 22.0
- W3C data 2023/07/20
from known-css-properties GitHub release notesWhat's Changed
New Contributors
Full Changelog: v0.33.0...v0.34.0
What's Changed
Full Changelog: v0.32.0...v0.33.0
What's Changed
Full Changelog: v0.31.0...v0.32.0
What's Changed
Full Changelog: v0.30.0...v0.31.0
Update properties
Update properties
Update dependencies
Full Changelog: v0.28.0...v0.29.0
Package name: picocolors
-
1.0.1 - 2024-05-14
- Updated color detection mechanism to work properly on Vercel Edge Runtime #64
- Remove use of recursion to avoid possible stack overflow for very long inputs #56
-
1.0.0 - 2021-10-13
- Removed several code elements to reduce the package size #31
- Fixed optional flag for
from picocolors GitHub release notesWhat's new?
What's new?
createColors()in TypeScript typings #34Package name: postcss
-
8.4.41 - 2024-08-05
- Fixed types (by @ nex3 and @ querkmachine).
- Cleaned up RegExps (by @ bluwy).
-
8.4.40 - 2024-07-24
- Moved to getter/setter in nodes types to help Sass team (by @ nex3).
-
8.4.39 - 2024-06-29
- Fixed
-
8.4.38 - 2024-03-20
- Fixed
-
8.4.37 - 2024-03-19
- Fixed
-
8.4.36 - 2024-03-17
- Fixed
-
8.4.35 - 2024-02-07
-
8.4.34 - 2024-02-05
-
8.4.33 - 2024-01-04
-
8.4.32 - 2023-12-02
-
8.4.31 - 2023-09-28
-
8.4.30 - 2023-09-18
-
8.4.29 - 2023-08-29
-
8.4.28 - 2023-08-15
-
8.4.27 - 2023-07-21
-
8.4.26 - 2023-07-13
-
8.4.25 - 2023-07-06
-
8.4.24 - 2023-05-28
from postcss GitHub release notesCssSyntaxErrortypes (by @ romainmenke).endIndex: 0in errors and warnings (by @ romainmenke).original.column are not numberserror in another case.original.column are not numberserror on broken previous source map.Package name: postcss-resolve-nested-selector
-
0.1.6 - 2024-08-12
-
0.1.5 - 2024-08-08
-
0.1.4 - 2024-07-23
-
0.1.3 - 2024-07-23
-
0.1.1 - 2016-02-19
from postcss-resolve-nested-selector GitHub release notesPackage name: postcss-selector-parser
-
6.1.2 - 2024-08-12
- Fixed: erroneous trailing combinators in pseudos
-
6.1.1 - 2024-07-11
- Fixed: improve typings of constructor helpers (#292)
-
6.1.0 - 2024-05-22
- Feature: add
-
6.0.16 - 2024-03-13
- Fixed: add missing
-
6.0.15 - 2023-12-29
- Fixed: Node#prev and Node#next type for the first/last node
-
6.0.14 - 2023-12-25
- Fixed: type definitions
-
6.0.13 - 2023-05-15
- Fixed: throw on unexpected pipe symbols
from postcss-selector-parser GitHub release notes6.1.2
6.1.1
6.1.0
sourceIndextoSelectornodes (#290)6.0.16
indexargument toeach/walkcallback types (#289)6.0.15
6.0.14
6.0.13
Package name: supports-hyperlinks
-
3.1.0 - 2024-08-20
- Add support for Windows Terminal (#8) e161d1d
-
3.0.0 - 2023-03-08
- Require Node.js 14
- Add TypeScript types (#21) a2546da
from supports-hyperlinks GitHub release notesv3.0.0...v3.1.0
Breaking
Improvements
v2.3.0...v3.0.0
Package name: table
-
6.8.2 - 2024-03-26
- Generate larger tables more quickly (#224) (1a39e0c)
-
6.8.1 - 2022-11-02
- Correct ansi cell width calculation (#214) (28e8e6e)
from table GitHub release notes6.8.2 (2024-03-26)
Bug Fixes
6.8.1 (2022-11-02)
Bug Fixes
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: