Skip to content

fix(@angular-devkit/build-angular): upgrade postcss to 8.5.12#33070

Merged
alan-agius4 merged 1 commit intoangular:19.2.xfrom
alan-agius4:postcss-19
Apr 28, 2026
Merged

fix(@angular-devkit/build-angular): upgrade postcss to 8.5.12#33070
alan-agius4 merged 1 commit intoangular:19.2.xfrom
alan-agius4:postcss-19

Conversation

@alan-agius4
Copy link
Copy Markdown
Collaborator

This addresses GHSA-qx2v-qp2m-jg93

Fixes: #33067

@alan-agius4 alan-agius4 requested a review from clydin April 28, 2026 09:23
@alan-agius4 alan-agius4 added action: review The PR is still awaiting reviews from at least one requested reviewer target: lts This PR is targeting a version currently in long-term support labels Apr 28, 2026
@alan-agius4 alan-agius4 linked an issue Apr 28, 2026 that may be closed by this pull request
1 task
Copy link
Copy Markdown

@gemini-code-assist gemini-code-assist Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the postcss dependency from version 8.5.2 to 8.5.12 in the root and package-level package.json files, with corresponding updates in pnpm-lock.yaml. Feedback suggests that the old, potentially vulnerable versions of postcss and nanoid still persist in the lockfile and should be pruned if they are no longer required to avoid triggering security scanners.

Comment thread pnpm-lock.yaml
@alan-agius4 alan-agius4 added action: merge The PR is ready for merge by the caretaker and removed action: review The PR is still awaiting reviews from at least one requested reviewer labels Apr 28, 2026
@alan-agius4 alan-agius4 merged commit 49ae0ad into angular:19.2.x Apr 28, 2026
54 of 56 checks passed
@alan-agius4 alan-agius4 deleted the postcss-19 branch April 28, 2026 11:32
@alan-agius4
Copy link
Copy Markdown
Collaborator Author

This PR was merged into the repository. The changes were merged into the following branches:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action: merge The PR is ready for merge by the caretaker area: @angular-devkit/build-angular target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: vulnerability found in transitive dependency postcss

2 participants