hexojs / hexo-asset-pipeline

A hexo plugin to minify/optimize HTML, CSS, JS and images. Supports revisioning of assets.
29 stars 16 forks source link

Bump clean-css from 4.2.4 to 5.2.3 #136

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps clean-css from 4.2.4 to 5.2.3.

Changelog

Sourced from clean-css's changelog.

5.2.3 / 2022-01-26

  • Fixed issue #1185 - keeping comments inside variables.
  • Fixed issue #1194 - unexpected end of JSON input when source map is empty.

5.2.2 / 2021-10-21

  • Fixed an unsafe data URI regex, which, when clean-css is used as a service, could be used in a DOS attack.

5.2.1 / 2021-09-30

  • Fixed issue #1186 - bad error handling in batch mode with promises.

5.2.0 / 2021-09-25

  • Fixed issue #1180 - properly handle empty variable values.

5.1.5 / 2021-08-05

  • Fixed issue #1178 - fixes lack of space removal in variable blocks.

5.1.4 / 2021-07-29

  • Fixed issue #1177 - fix to missing local imports when only remote ones allowed.

5.1.3 / 2021-06-25

  • Fixed issue #1160 - keep zero units when inside multiple functions.
  • Fixed issue #1161 - extra whitespace in URLs.
  • Fixed issue #1166 - incorrect compoment splitting when empty multiplex part.

5.1.2 / 2021-03-19

  • Fixed issue #996 - space removed from pseudo classes.

5.1.1 / 2021-03-03

  • Fixed issue #1156 - invalid hsl/hsla validation in level 2 optimizations.

5.1.0 / 2021-02-18

... (truncated)

Commits


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Superseded by #137.