🚨 [security] [js] Update stylelint 17.14.1 → 17.15.0 (minor) - #877
Open
depfu[bot] wants to merge 1 commit into
Open
🚨 [security] [js] Update stylelint 17.14.1 → 17.15.0 (minor)#877depfu[bot] wants to merge 1 commit into
depfu[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🚨 Your current dependencies have known security vulnerabilities 🚨
This dependency update fixes known security vulnerabilities. Please see the details below and assess their impact carefully. We recommend to merge and deploy this as soon as possible!
Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.
What changed?
✳️ stylelint (17.14.1 → 17.15.0) · Repo · Changelog
Release Notes
17.15.0
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 56 commits:
Release 17.15.0 (#9484)Fix `custom-property-no-missing-var-function` false positives for anchor positioning (#9466)Bump @humanfs/node from 0.16.6 to 0.16.8 (#9480)Bump fast-uri from 3.1.5 to 3.1.7 (#9481)Bump the jest group across 1 directory with 2 updates (#9476)Bump browserslist from 4.28.4 to 4.28.8 (#9479)Add `ignoreFunctions: []` to `color-named` and `color-no-hex` (#9463)Bump postcss-import from 16.1.1 to 16.2.0 in the postcss group (#9477)Bump globby from 16.2.3 to 16.2.4 (#9478)Bump @csstools/css-syntax-patches-for-csstree from 1.1.8 to 1.1.9 in the csstree group (#9474)Bump the eslint group with 2 updates (#9475)Fix `selector-no-invalid` false negatives for pseudo-elements, combinators and nested `:has()` (#9452)Fix `declaration-property-max-values` false positives for interpolated inline expressions (#9437)Add `selector-no-unmatchable` (#9451)Bump string-width from 8.2.1 to 8.2.2 (#9462)Bump colord from 2.9.3 to 2.10.0 (#9461)Bump eslint from 10.8.1 to 10.9.0 in the eslint group (#9459)Bump @changesets/cli from 3.0.0 to 3.0.1 in the changesets group (#9458)Add `--source` and `--config` options to rule benchmark script (#9455)Document `referenceFiles` more prominently in customising guide (#9454)Bump tinybench from 6.0.2 to 6.1.3 (#9449)Bump @csstools/css-syntax-patches-for-csstree from 1.1.7 to 1.1.8 in the csstree group (#9446)Bump npm-run-all2 from 9.0.2 to 9.0.3 (#9448)Bump vulnerable packages via `npm audit fix` (#9444)Bump the changesets group with 2 updates (#9440)Bump the eslint group across 1 directory with 2 updates (#9441)Bump the postcss group with 3 updates (#9442)Bump globby from 16.2.2 to 16.2.3 (#9443)Bump the typescript group across 1 directory with 2 updates (#9432)Respect default cooldown period for Dependabot (#9439)Bump the eslint group with 2 updates (#9431)Bump lint-staged from 17.0.8 to 17.3.0 (#9434)Bump globby from 16.2.1 to 16.2.2 (#9435)Bump prettier from 3.9.5 to 3.9.6 (#9417)Bump @changesets/cli from 2.31.0 to 2.31.1 in the changesets group across 1 directory (#9414)Bump fast-uri from 3.1.4 to 3.1.5 (#9430)Bump postcss from 8.5.21 to 8.5.25 (#9429)Bump @csstools/css-syntax-patches-for-csstree from 1.1.6 to 1.1.7 in the csstree group across 1 directory (#9428)Bump the csstools-parser group with 2 updates (#9427)Document "ready to implement" label in the contributing guide (#9425)Fix unknown effort workflow (#9421)Bump actions/checkout from 7.0.0 to 7.0.1 (#9413)Bump eslint-plugin-jest from 29.15.4 to 29.15.5 in the eslint group (#9415)Bump postcss from 8.5.19 to 8.5.21 in the postcss group (#9416)Fix `declaration-block-no-redundant-longhand-properties` autofix for `font` shorthand (#9402)Bump the stylelint-actions group with 5 updates (#9403)Bump fast-uri from 3.1.2 to 3.1.4 (#9410)Bump shell-quote from 1.8.4 to 1.10.0 (#9411)Bump actions/setup-node from 6.4.0 to 7.0.0 (#9404)Bump eslint from 10.6.0 to 10.7.0 in the eslint group (#9405)Bump postcss from 8.5.16 to 8.5.19 in the postcss group (#9406)Bump prettier from 3.9.4 to 3.9.5 (#9409)Bump ignore from 7.0.5 to 7.0.6 (#9408)Document summary and item order of latest release in CHANGELOG (#9401)Fix doubled periods in CHANGELOG.md entries (#9399)Use `node-version: latest` instead of `lts/*` for `actions/setup-node` (#9398)Release Notes
2.10.0 (from changelog)
2.9.7 (from changelog)
2.9.6 (from changelog)
2.9.5 (from changelog)
2.9.4 (from changelog)
Does any of this look wrong? Please let us know.
Release Notes
1.20.3
1.20.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 3 commits:
Bumped v1.20.3Bumped v1.20.2fix: preserve running count when aborting queued tasks (#107)Release Notes
16.2.4
16.2.3
16.2.2
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 7 commits:
16.2.4Fix `ignore` option disabling the `gitignore` option16.2.3Fix backslash-escaped `.gitignore` rulesMeta tweaks16.2.2Fix: Do not enumerate ignored directories with `gitignore` optionSecurity Advisories 🚨
🚨 nanoid: custom generators can loop indefinitely when size is zero
Release Notes
3.3.18
3.3.17
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 5 commits:
Release 3.3.18 versionUpdate CI actionUpdate index.native.js (#606)Release 3.3.17 versionSync 0 size behaviour with PostCSS 5Release Notes
8.5.28
8.5.27
8.5.26
8.5.25
8.5.24
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 35 commits:
Release 8.5.28 versionTypoAdd missed release notesRelease 8.5.27 versionFix linterUpdate dependenciesKeep non-annotation comments when the processor has no plugins (#2150)Fix linkAdd GitHub Sponsors linkAdd CodeRabbit sponsor (#2145)Fix chinese print not work (#2144)Drop whitespace-only values from list.space() (#2141)Fix `'source' does not exist in type 'DeclarationProps'` error (#2138)Update dependenciesFix rule end offset when spaces precede its own semicolon (#2135)Keep empty values in the middle and at the start of list.comma() (#2134)Do not terminate a hack-prefixed property before a comment (#2126)Release 8.5.26 versionUpdate CIFix Rule#selectors losing the empty selector (#2129)TypoResolve symlinks before the previous-source-map containment check (#2125)Update dependenciesUpdate lock fileUpgrade nanoid to fix infinite loop on zero size (#2124)Explain how to type plugin optionsdocs: show ESM and TypeScript plugin declaration (#2118)Release 8.5.25 versionFix 8.5.17 visitor regressionAdd supply chain security requirement to PostCSS plugin guidefix: return empty array for empty string in list.split (#2121)Release 8.5.24 versionUpdate dependenciesPreserve the BOM when stringifying (#2119)Fix types checkRelease Notes
7.1.6
7.1.5
Does any of this look wrong? Please let us know.
Commits
See the full diff on Github. The new version differs by 8 commits:
7.1.6fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability7.1.5fix: TypeError on unclosed `[`, `(` and trailing `|` (#330)fix: preserve whitespace before a `*` namespace in attribute selectors (#325)fix: don't treat a non-prefix token before `|` as a namespace (#324)chore(deps-dev): bump postcss from 8.5.18 to 8.5.23 (#331)chore(deps-dev): bump postcss from 8.5.15 to 8.5.18 (#328)🆕 ignore (added, 7.0.8)
Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with
@depfu rebase.All Depfu comment commands