Skip to content

Replace cssnano with cssnano-patched #720

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from
Closed

Replace cssnano with cssnano-patched #720

wants to merge 1 commit into from

Conversation

bwendt-mylo
Copy link

What kind of change does this PR introduce?

This fixes a security vulnerability inherited from cssnano (v3 branch is no longer maintained)

Did you add tests for your changes?
No

If relevant, did you update the README?
Not relevant

Summary
The cssnano dependency is on v3.10.0 but that branch is no longer being maintained. A security vulnerability was found in a dependency of cssnano. I've forked the cssnano repo at the v3.10.0 commit, updated the vulnerable dependency, and then published the changes to cssnano-patched.

Does this PR introduce a breaking change?

No

Other information
Here's a link to the root vulnerability

@jsf-clabot
Copy link

jsf-clabot commented May 22, 2018

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants