Skip to content

Build(deps): Bump postcss from 8.5.19 to 8.5.25 - #150

Merged
kdr merged 1 commit into
mainfrom
dependabot/npm_and_yarn/postcss-8.5.25
Aug 5, 2026
Merged

Build(deps): Bump postcss from 8.5.19 to 8.5.25#150
kdr merged 1 commit into
mainfrom
dependabot/npm_and_yarn/postcss-8.5.25

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.19 to 8.5.25.

Release notes

Sourced from postcss's releases.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

Changelog

Sourced from postcss's changelog.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note

Low Risk
Patch-level dev dependency lockfile update with no runtime code changes; minor behavior changes in CSS processing are possible but typical for postcss patch releases.

Overview
Updates the lockfile so postcss moves from 8.5.19 to 8.5.25 (dev dependency). nanoid is bumped from 3.3.15 to 3.3.17 as postcss’s transitive dependency.

There are no application source changes. The newer postcss releases include bug fixes (AST/visitor behavior, list.split(), BOM handling, semicolon/comment edge cases) and 8.5.23 tightens source-map loading when opts.from is missing.

Reviewed by Cursor Bugbot for commit c55a438. Bugbot is set up for automated code reviews on this repo. Configure here.

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.19 to 8.5.25.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.19...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 5, 2026
@kdr
kdr merged commit 8f4b567 into main Aug 5, 2026
5 checks passed
@kdr
kdr deleted the dependabot/npm_and_yarn/postcss-8.5.25 branch August 5, 2026 05:14
kdr added a commit that referenced this pull request Aug 5, 2026
… add --all abort test (#152)

Closes out the current Dependabot security sweep
(https://github.com/kdr/overcast/security/dependabot).

## What

- **vscode/package-lock.json (lockfile-only, within existing semver
ranges):**
- `postcss` 8.5.19 → 8.5.25 — attacker-controlled `sourceMappingURL`
reads arbitrary `.map` files when `from` is unset (alert #22; via
tsup/vite)
- `brace-expansion` 5.0.8 → 5.0.9 — DoS via unbounded intermediate
arrays (flagged by `npm audit`, no open Dependabot PR; via
`@vscode/vsce` → minimatch)
  - vscode `npm audit` after: **0 vulnerabilities**
- **test/unit/face-index.test.ts:** deterministic abort point for
`aborting during add --all backpressure stops before the next wave`. The
100 ms wall-clock abort raced wave 0's child processes under suite load:
landing mid-spawn surfaces node's generic `AbortError` (reason demoted
to `cause`) instead of `signal.reason`, and wave-0 membership may not be
written yet — intermittently failing both assertions (this reddened
#149's CI and one local full run). The test now aborts only once the
wave-0 member is visibly written, i.e. provably inside the 60 s
between-wave settle sleep whose abort path rejects with the reason; if
the run settles first the poll bails so the real error surfaces through
`assert.rejects`.

## Triage context (same sweep, handled outside this PR)

- Merged: #150 (root postcss 8.5.25), #151 (vscode fast-uri 3.1.5) —
both green; alerts #21/#23 auto-closed.
- Closed: #149 (vscode postcss) as superseded — its only CI failure was
the flaky test fixed here; its bump is included here.
- Already on main: #147 (vscode undici 7.29.0).

## Not addressed — upstream-blocked (alerts #19, #11–13)

Root `brace-expansion@5.0.7` (high) and `undici@8.5.0` (3 medium) are
pinned inside `@earendil-works/pi-coding-agent`'s published
`npm-shrinkwrap.json`. Root `overrides` and `npm audit fix` silently
no-op on the shrinkwrapped subtree (audit even prints "fix available",
then changes nothing), and pi-coding-agent 0.83.0 still declares
`undici@8.5.0` exactly — the only real fix is an upstream pi release
with a refreshed shrinkwrap, then a reviewed exact-pin bump. Interim
reachability: pi 0.83.0's undici use has no cache/retry interceptors
(the CVE surfaces), and its minimatch patterns are config-driven, not
attacker input.

## Verification (all on this branch, full unfiltered output)

| suite | result |
| --- | --- |
| `npm test` | **1319/1319 pass**, exit 0 |
| `npm run test:e2e` (offline) | **367/367 passed, 0 failed**, exit 0 |
| `npm run typecheck` | exit 0 |
| vscode `typecheck` / `build` / `test` / `package` | exit 0 / exit 0 /
**56/56** / `.vsix` packaged (vsce = the brace-expansion consumer) |
| `npm run test:e2e:live` (compiled **bun binary**) | **767/778 passed,
11 failed** |
| live re-run of the 5 failing cases (same binary) | **187/194 passed, 7
failed** — 4 recovered (transient: Apify `x` no-hits, brain-LLM `see`
empty responses) |

The 7 persistent live failures are external-data conditions, not code:
Apify lens actor returning no hits today (4 assertions), `chain:btc`
head tx currently **unconfirmed** so `payload.created` is null by design
(`chain.sh` maps `status.block_time // null`), and one borderline CLIP
text×image ranking. The bun binary under test is content-identical to
main's (this diff is vscode-lockfile + a unit test only; root lockfile
byte-identical after rebase), so those reflect main's current live
status, not this PR.

Flake-fix determinism: patched test file green 3×3 isolated runs + full
suite green (previously failed the full-suite run).

## Follow-up suggestions (not in this PR)

- Watch pi upstream for a shrinkwrap refresh to clear alerts #19/#11–13
via a reviewed pin bump.
- The live `20b` chain case could tolerate an unconfirmed head tx
(assert `created` only on confirmed txs).

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Lockfile-only dependency patches plus a unit-test timing fix; no
production runtime or application logic changes.
> 
> **Overview**
> **Dependency updates (vscode lockfile only):** bumps `postcss` to
8.5.25 and `brace-expansion` to 5.0.9 within existing semver ranges to
address Dependabot/npm audit findings (source map path handling and
minimatch DoS).
> 
> **Test stability:** the `index add --all` backpressure abort test no
longer fires `AbortController` after a fixed 100ms. It waits until wave
0 has written at least one index member (or the run settles), so abort
happens during the long between-wave `sleep` where rejection uses
`signal.reason`, avoiding flaky `assert.rejects` and wrong member counts
under full-suite load.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
836b3fb. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
@kdr kdr mentioned this pull request Aug 5, 2026
kdr added a commit that referenced this pull request Aug 5, 2026
Patch version bump so the Dependabot lockfile fixes
(#147/#150/#151/#152) ship to npm.

`npm version patch --no-git-tag-version` per RELEASING.md —
`sync-version.mjs` propagated 0.0.15 to `src/version.ts`,
`.claude-plugin/plugin.json`, `.claude-plugin/marketplace.json`, and
`vscode/package.json`+lock (7 files, verified with `sync-version.mjs
--check`).

After merge, cut the tag on main to trigger the npm publish + binary
release train:

```bash
git checkout main && git pull && git tag v0.0.15 && git push origin v0.0.15
```

## Verification

| suite | result |
| --- | --- |
| `npm test` | **1319/1319 pass**, exit 0 |
| `npm run test:e2e` (offline) | **367/367 passed, 0 failed**, exit 0 |
| `node scripts/sync-version.mjs --check` | all surfaces match 0.0.15 |
| `node dist/bin/overcast.js --version --json` |
`{"overcast":"0.0.15","pi":"0.82.1","node":"24.17.0"}` |

<!-- CURSOR_SUMMARY -->
---

> [!NOTE]
> **Low Risk**
> Version-metadata-only bump with no runtime or security logic changes.
> 
> **Overview**
> **Patch release** that bumps the published version from **0.0.14** to
**0.0.15** so recent lockfile/dependency fixes can ship on npm and the
release train.
> 
> The change is limited to synchronized version strings: root
`package.json` / `package-lock.json`, `OVERCAST_VERSION` in
`src/version.ts`, Claude plugin metadata (`plugin.json`,
`marketplace.json`), and the VS Code extension `package.json` /
lockfile. No application logic or behavior changes in this diff.
> 
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
2501773. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant