chore(deps): bump postcss from 8.5.8 to 8.5.15 in /frontend#2265
chore(deps): bump postcss from 8.5.8 to 8.5.15 in /frontend#2265dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.8 to 8.5.15. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.8...8.5.15) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.15 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Greptile SummaryThis PR bumps
Confidence Score: 5/5Safe to merge — a routine patch-level dependency bump with no breaking changes and important security fixes included. The change is a single-line version bump within the same semver minor, updating postcss from 8.5.8 to 8.5.15. All intermediate releases are patch fixes (security, performance, regression); no API changes were introduced. The ^ range in package.json means this was already installable before the bump — the PR simply makes the minimum pinned version explicit. No files require special attention.
|
| Filename | Overview |
|---|---|
| frontend/package.json | Single-line bump of postcss from ^8.5.8 to ^8.5.15; picks up security fixes and performance improvements with no API-breaking changes. |
Reviews (1): Last reviewed commit: "chore(deps): bump postcss from 8.5.8 to ..." | Re-trigger Greptile
Bumps postcss from 8.5.8 to 8.5.15.
Release notes
Sourced from postcss's releases.
Changelog
Sourced from postcss's changelog.
Commits
eae46dbRelease 8.5.15 version79508ffUpdate CI actionsb128e21Speed up declaration parsing by avoiding creating new array on each token9825dcaFix code format55789c8Update dependencies84fbbe9Install older pnpm action for old Node.js9f860bdRevert pnpm action for old Node.js0877198Update CI actionsb2d1a33Fix linter warnings0700dacMerge pull request #2088 from rootvector2/add-oss-fuzz-harnessDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)