spresnac / logcrawler2-server

2 stars 0 forks source link

[Snyk] Upgrade tailwindcss from 3.4.4 to 3.4.6 #84

Open spresnac opened 3 months ago

spresnac commented 3 months ago

snyk-top-banner

Snyk has created this PR to upgrade tailwindcss from 3.4.4 to 3.4.6.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Inefficient Regular Expression Complexity
SNYK-JS-MICROMATCH-6838728
375 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JS-SERIALIZEJAVASCRIPT-6147607
375 Proof of Concept
Release notes
Package name: tailwindcss
  • 3.4.6 - 2024-07-16

    Fixed

    • Fix detection of some utilities in Slim/Pug templates (#14006)

    Changed

    • Loosen :is() wrapping rules when using an important selector (#13900)
  • 3.4.5 - 2024-07-15

    Fixed

    • Disable automatic var() injection for anchor properties (#13826)
    • Use no value instead of blur(0px) for backdrop-blur-none and blur-none utilities (#13830)
    • Add .mts and .cts config file detection (#13940)
    • Don't generate utilities like px-1 unnecessarily when using utilities like px-1.5 (#13959)
    • Always generate -webkit-backdrop-filter for backdrop-* utilities (#13997)
  • 3.4.4 - 2024-06-05

    Fixed

    • Make it possible to use multiple <alpha-value> placeholders in a single color definition (#13740)
    • Don't prefix classes in arbitrary values of has-*, group-has-*, and peer-has-* variants (#13770)
    • Support negative values for {col,row}-{start,end} utilities (#13781)
    • Update embedded browserslist database (#13792)
from tailwindcss GitHub release notes

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information: