Upgrade postcss-selector-parser to 7.1.6: fixes GHSA-rj75-hqrm-r3gf #11
postcss-selector-parser (npm) has known vulnerabilities with a fix in 7.1.6. Upgrade it to 7.1.6 or later everywhere it is locked, keeping other changes to what the upgrade needs.
| Advisory | Severity | Affected | Fixed in | Summary |
|---|---|---|---|---|
| GHSA-rj75-hqrm-r3gf | medium | 6.1.4 | 7.1.6 | PostCSS: Quadratic complexity in flat selector parsing allows CPU exhaustion |
Locked in: package-lock.json (6.1.4).
The acceptance checks pass once no lockfile resolves a vulnerable version and the tests still pass. If the fix needs a major upgrade that breaks the build, change the code that depends on it in the same pull request.
Opened by g1t's dependency upkeep. Turn it off for this project on its Security page.
Pull requests
1 for this issue, none merged