Socket
Socket
Sign inDemoInstall

postcss

Package Overview
Dependencies
8
Maintainers
1
Versions
252
Alerts
File Explorer

Advanced tools

Install Socket

Detect and block malicious and high-risk dependencies

Install

Comparing version 7.0.35 to 7.0.36

3

CHANGELOG.md
# Change Log
This project adheres to [Semantic Versioning](http://semver.org/).
## 7.0.36
* Backport ReDoS vulnerabilities from PostCSS 8.
## 7.0.35

@@ -5,0 +8,0 @@ * Add migration guide link to PostCSS 8 error text.

6

lib/previous-map.js

@@ -89,7 +89,7 @@ "use strict";

_proto.getAnnotationURL = function getAnnotationURL(sourceMapString) {
return sourceMapString.match(/\/\*\s*# sourceMappingURL=(.*)\s*\*\//)[1].trim();
return sourceMapString.match(/\/\*\s*# sourceMappingURL=((?:(?!sourceMappingURL=).)*)\*\//)[1].trim();
};
_proto.loadAnnotation = function loadAnnotation(css) {
var annotations = css.match(/\/\*\s*# sourceMappingURL=(.*)\s*\*\//mg);
var annotations = css.match(/\/\*\s*# sourceMappingURL=(?:(?!sourceMappingURL=).)*\*\//gm);

@@ -173,2 +173,2 @@ if (annotations && annotations.length > 0) {

module.exports = exports.default;
//# sourceMappingURL=data:application/json;charset=utf8;base64,
//# sourceMappingURL=data:application/json;charset=utf8;base64,

@@ -45,3 +45,3 @@ "use strict";

*/
this.version = '7.0.35';
this.version = '7.0.36';
/**

@@ -265,2 +265,2 @@ * Plugins added to this processor.

module.exports = exports.default;
//# sourceMappingURL=data:application/json;charset=utf8;base64,
//# sourceMappingURL=data:application/json;charset=utf8;base64,
{
"name": "postcss",
"version": "7.0.35",
"version": "7.0.36",
"description": "Tool for transforming styles with JS plugins",

@@ -8,3 +8,13 @@ "engines": {

},
"keywords": ["css", "postcss", "rework", "preprocessor", "parser", "source map", "transform", "manipulation", "transpiler"],
"keywords": [
"css",
"postcss",
"rework",
"preprocessor",
"parser",
"source map",
"transform",
"manipulation",
"transpiler"
],
"funding": {

@@ -25,7 +35,2 @@ "type": "opencollective",

"types": "lib/postcss.d.ts",
"husky": {
"hooks": {
"pre-commit": "lint-staged"
}
},
"browser": {

@@ -36,4 +41,3 @@ "./lib/terminal-highlight": false,

"fs": false
},
"browserslist": ["and_chr 71", "and_ff 64", "and_qq 1.2", "and_uc 11.8", "android 67", "android 4.4.3-4.4.4", "baidu 7.12", "chrome 73", "chrome 72", "edge 18", "edge 17", "firefox 66", "firefox 65", "ios_saf 12.0-12.1", "ios_saf 11.3-11.4", "node 6.17.0", "op_mini all", "op_mob 46", "opera 58", "opera 57", "safari 12", "safari 11.1", "samsung 8.2", "samsung 7.2-7.4"]
}
}
}
SocketSocket SOC 2 Logo

Product

  • Package Alerts
  • Integrations
  • Docs
  • Pricing
  • FAQ
  • Roadmap

Stay in touch

Get open source security insights delivered straight into your inbox.


  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc