chore(deps): Bump postcss from 8.5.8 to 8.5.15 in /tools/visual-chromatic#164
Conversation
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.8 to 8.5.15. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.8...8.5.15) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.15 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Skipping PR review because a bot author is detected. If you want to trigger CodeAnt AI, comment |
|
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Terraform | May 20, 2026 12:04a.m. | Review ↗ | |
| SQL | May 20, 2026 12:04a.m. | Review ↗ | |
| Rust | May 20, 2026 12:04a.m. | Review ↗ | |
| Shell | May 20, 2026 12:04a.m. | Review ↗ | |
| Ruby | May 20, 2026 12:04a.m. | Review ↗ | |
| PHP | May 20, 2026 12:04a.m. | Review ↗ | |
| Kotlin | May 20, 2026 12:04a.m. | Review ↗ | |
| Swift | May 20, 2026 12:04a.m. | Review ↗ | |
| Scala | May 20, 2026 12:04a.m. | Review ↗ | |
| Python | May 20, 2026 12:04a.m. | Review ↗ | |
| JavaScript | May 20, 2026 12:04a.m. | Review ↗ | |
| Java | May 20, 2026 12:04a.m. | Review ↗ | |
| Go | May 20, 2026 12:04a.m. | Review ↗ | |
| Docker | May 20, 2026 12:04a.m. | Review ↗ | |
| C & C++ | May 20, 2026 12:04a.m. | Review ↗ | |
| Ansible | May 20, 2026 12:04a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
Up to standards ✅🟢 Issues
|



Bumps postcss from 8.5.8 to 8.5.15.
Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
eae46dbRelease 8.5.15 version79508ffUpdate CI actionsb128e21Speed up declaration parsing by avoiding creating new array on each token9825dcaFix code format55789c8Update dependencies84fbbe9Install older pnpm action for old Node.js9f860bdRevert pnpm action for old Node.js0877198Update CI actionsb2d1a33Fix linter warnings0700dacMerge pull request #2088 from rootvector2/add-oss-fuzz-harnessDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Summary by cubic
Upgrade
postcssto 8.5.15 intools/visual-chromaticto pick up security fixes and parsing performance improvements. This patches XSS and arbitrary file read issues and speeds up declaration parsing.postcss8.5.8 → 8.5.15nanoid3.3.11 → 3.3.12 (transitive)Written for commit 1ac606e. Summary will update on new commits. Review in cubic