From 044e3ecc17947bab59662e85e74ae75d4b90d8e8 Mon Sep 17 00:00:00 2001 From: Kokila-chandrakar Date: Sun, 7 Jun 2026 23:12:45 +0530 Subject: [PATCH 1/3] fix: resolve postcss XSS vulnerability (CVE - moderate severity) --- package-lock.json | 6 +++--- package.json | 7 +++++-- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/package-lock.json b/package-lock.json index 5784f0afd..ed5397c8e 100644 --- a/package-lock.json +++ b/package-lock.json @@ -7852,8 +7852,8 @@ } }, "node_modules/next/node_modules/postcss": { - "version": "8.4.31", - "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.4.31.tgz", + "version": "8.5.15", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.15.tgz", "integrity": "sha512-PS08Iboia9mts/2ygV3eLpY5ghnUcfLV/EXTOW1E2qYxJKGGBUtNjN76FYHnMs36RmARn41bC0AZmn+rR0OVpQ==", "funding": [ { @@ -10418,4 +10418,4 @@ } } } -} +} \ No newline at end of file diff --git a/package.json b/package.json index 14285ddad..6456aa928 100644 --- a/package.json +++ b/package.json @@ -57,12 +57,15 @@ "jsdom": "^29.0.2", "lint-staged": "^15.2.11", "node-mocks-http": "^1.17.2", - "postcss": "^8.5.9", + "postcss": "^8.5.10", "prettier": "^3.8.3", "react-is": "^19.2.6", "tailwindcss": "^4.2.2", "tsx": "^4.22.2", "typescript": "^5", "vitest": "^4.1.4" + }, + "overrides": { + "postcss": ">=8.5.10" } -} +} \ No newline at end of file From 263af9b6680d9246597bffb4885632bc2a50acbe Mon Sep 17 00:00:00 2001 From: Kokila-chandrakar Date: Sun, 7 Jun 2026 23:26:26 +0530 Subject: [PATCH 2/3] fix: remove conflicting postcss override (direct devDependency already satisfies >=8.5.10) --- package.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index 6456aa928..aaaefc327 100644 --- a/package.json +++ b/package.json @@ -66,6 +66,6 @@ "vitest": "^4.1.4" }, "overrides": { - "postcss": ">=8.5.10" + "postcss": "^8.5.10" } -} \ No newline at end of file +} From 26a2fe89ef346c956d14e14e3216ac17bb8fe051 Mon Sep 17 00:00:00 2001 From: Kokila-chandrakar Date: Sun, 7 Jun 2026 23:35:59 +0530 Subject: [PATCH 3/3] fix: sync package-lock.json with updated postcss version --- package-lock.json | 30 +++++------------------------- 1 file changed, 5 insertions(+), 25 deletions(-) diff --git a/package-lock.json b/package-lock.json index 9095a4cb4..0cc039028 100644 --- a/package-lock.json +++ b/package-lock.json @@ -61,7 +61,7 @@ "jsdom": "^29.1.1", "lint-staged": "^15.2.11", "node-mocks-http": "^1.17.2", - "postcss": "^8.5.9", + "postcss": "^8.5.10", "prettier": "^3.8.3", "react-is": "^19.2.6", "tailwindcss": "^4.2.2", @@ -1885,9 +1885,6 @@ "cpu": [ "arm64" ], - "libc": [ - "glibc" - ], "license": "MIT", "optional": true, "os": [ @@ -1904,9 +1901,6 @@ "cpu": [ "arm64" ], - "libc": [ - "musl" - ], "license": "MIT", "optional": true, "os": [ @@ -1923,9 +1917,6 @@ "cpu": [ "riscv64" ], - "libc": [ - "glibc" - ], "license": "MIT", "optional": true, "os": [ @@ -1942,9 +1933,6 @@ "cpu": [ "x64" ], - "libc": [ - "glibc" - ], "license": "MIT", "optional": true, "os": [ @@ -1961,9 +1949,6 @@ "cpu": [ "x64" ], - "libc": [ - "musl" - ], "license": "MIT", "optional": true, "os": [ @@ -3282,7 +3267,7 @@ "version": "19.2.16", "resolved": "https://registry.npmjs.org/@types/react/-/react-19.2.16.tgz", "integrity": "sha512-esJiCAnl0kfpNdE69f3So4WJUXy95dLZydX0KwK46riIHDzHM7O9Vtf9xCHW0PXIqvgqNrswl522kA/5yx+F4w==", - "dev": true, + "devOptional": true, "license": "MIT", "dependencies": { "csstype": "^3.2.2" @@ -8871,8 +8856,8 @@ } }, "node_modules/next/node_modules/postcss": { - "version": "8.5.15", - "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.5.15.tgz", + "version": "8.4.31", + "resolved": "https://registry.npmjs.org/postcss/-/postcss-8.4.31.tgz", "integrity": "sha512-PS08Iboia9mts/2ygV3eLpY5ghnUcfLV/EXTOW1E2qYxJKGGBUtNjN76FYHnMs36RmARn41bC0AZmn+rR0OVpQ==", "funding": [ { @@ -9641,11 +9626,6 @@ } }, "node_modules/react-is": { - - "version": "19.2.7", - "resolved": "https://registry.npmjs.org/react-is/-/react-is-19.2.7.tgz", - "integrity": "sha512-kZFnouyVv7eP/Phmrlo9FK+zcAdriZJvzxXHF1Sl1P377WSGe2G/JxVolhTrB/jeV47lKImhNUsijjHAAbcl/A==", - "dev": true, "version": "19.2.6", "resolved": "https://registry.npmjs.org/react-is/-/react-is-19.2.6.tgz", "integrity": "sha512-XjBR15BhXuylgWGuslhDKqlSayuqvqBX91BP8pauG8kd1zY8kotkNWbXksTCNRarse4kuGbe2kIY05ARtwNIvw==", @@ -11863,4 +11843,4 @@ } } } -} \ No newline at end of file +}