postcss / postcss-cli

CLI for postcss
Other
824 stars 93 forks source link

Update postcss-load-config version #449

Closed manugarg closed 1 year ago

manugarg commented 1 year ago

Earlier version depends on a yaml version that has a moderate security bug. See the following for more details: https://github.com/advisories/GHSA-f9xv-q969-pqx4

RyanZim commented 1 year ago

The current version is already defined with ^, so what's the point?

manugarg commented 1 year ago

Yes, fair enough. I didn't realize it won't be an issue (haven't worked with package.json files before). The fact that postcss-load-config changes their minimum yaml version made me think that postcss-cli would need that too.