Skip to content

deps(deps-dev): bump postcss from 8.5.23 to 8.5.25 in /docs in the all group across 1 directory - #1976

Open
dependabot[bot] wants to merge 1 commit into
edgefrom
dependabot/npm_and_yarn/docs/edge/all-14d799c0ca
Open

deps(deps-dev): bump postcss from 8.5.23 to 8.5.25 in /docs in the all group across 1 directory#1976
dependabot[bot] wants to merge 1 commit into
edgefrom
dependabot/npm_and_yarn/docs/edge/all-14d799c0ca

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 1 update in the /docs directory: postcss.

Updates postcss from 8.5.23 to 8.5.25

Release notes

Sourced from postcss's releases.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).
Changelog

Sourced from postcss's changelog.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 4, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 4, 2026 05:44
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Aug 4, 2026
@dependabot
dependabot Bot requested review from a team as code owners August 4, 2026 05:44
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Aug 4, 2026
@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/postcss 8.5.25 🟢 7.4
Details
CheckScoreReason
Maintained🟢 1030 commit(s) and 11 issue activity found in the last 90 days -- score normalized to 10
Packaging⚠️ -1packaging workflow not detected
Security-Policy🟢 10security policy file detected
Code-Review⚠️ 3Found 9/30 approved changesets -- score normalized to 3
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 3branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • docs/package-lock.json

@github-actions

github-actions Bot commented Aug 4, 2026

Copy link
Copy Markdown

Static Web App Preview

Environment Deployment
pr1976 View workflow run

Deployed from commit fededa05b1c167a7c912f12a22cd589439c34a14 via the publisher workflow.

@lakshmimsft

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps the all group with 1 update in the /docs directory: [postcss](https://github.com/postcss/postcss).


Updates `postcss` from 8.5.23 to 8.5.25
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.23...8.5.25)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.25
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps(deps-dev): bump postcss from 8.5.23 to 8.5.25 in /docs in the all group deps(deps-dev): bump postcss from 8.5.23 to 8.5.25 in /docs in the all group across 1 directory Aug 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/docs/edge/all-14d799c0ca branch from bc69931 to fededa0 Compare August 5, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant