Skip to content

chore(deps): bump postcss from 8.5.12 to 8.5.26 in /test-projects/expo-purchasely-test - #276

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/postcss-8.5.26
Closed

chore(deps): bump postcss from 8.5.12 to 8.5.26 in /test-projects/expo-purchasely-test#276
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/postcss-8.5.26

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 11, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss from 8.5.12 to 8.5.26.

Release notes

Sourced from postcss's releases.

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

8.5.15

  • Fixed declaration parsing performance (by @​homanp).

8.5.14

8.5.13

... (truncated)

Changelog

Sourced from postcss's changelog.

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.


@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 11, 2026
@greptile-apps

greptile-apps Bot commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-08-12) is posted on #271 (Issues are disabled on this repo; old host #269 — the PR this one supersedes — was closed on 08-11, #271 is the new host) — covers this PR plus #272, #273, #274, #275, #277. This PR: postcss 8.5.12→8.5.26 (minor, /test-projects/expo-purchasely-test), CI red on build-ios only (6/7 pass) — root cause identified as the Xcode 26 explicit-modules issue fixed by open PR #278. See #271 for the full table and next steps — nothing merges without a human go-ahead there.


Generated by Claude Code

Bumps [postcss](https://github.com/postcss/postcss) from 8.5.12 to 8.5.26.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.12...8.5.26)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.26
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/test-projects/expo-purchasely-test/postcss-8.5.26 branch from 717760b to 069ebe4 Compare August 20, 2026 10:02

Copy link
Copy Markdown

Dependabot PR Review — 2026-08-29

Note: Issues are disabled on this repo, so this review is posted directly on each of the 6 currently-open Dependabot PRs instead of a shared tracking issue (the process used on Purchasely-Firebase-Extension#498 and purchasely-support-app#266). Nothing has been merged, approved, or closed — this PR will only be merged after an explicit human go-ahead comment on it.

# Package Version Change Bump CI Mergeable Action
#276 (this PR) postcss (/test-projects/expo-purchasely-test) 8.5.12 → 8.5.26 patch 🟢 Green (7/7) blocked (no conflict) Auto-merge candidate
#277 nanoid 3.3.11 → 3.3.18 patch 🔴 build-ios failing, other 6 green blocked CI Failing
#275 nanoid (test-projects) 3.3.11 → 3.3.18 patch 🔴 build-ios failing, other 6 green blocked CI Failing, same pattern as #277
#274 undici 7.28.0 → 7.29.0 minor 🔴 All 7 jobs failing blocked CI Failing — security-relevant, needs root cause
#273 undici (test-projects) 8.5.0 → 8.10.0 minor 🟢 Green (7/7) was dirty — rebase requested this cycle Auto-merge candidate once rebased
#272 fast-uri (test-projects) 4.1.1 → 4.1.2 patch 🟢 Green (7/7) was dirty — rebase requested this cycle Auto-merge candidate once rebased

This PR (#276) is a clean patch bump with CI fully green and no conflict — no known reason to hold it. Waiting on an explicit "merge #276" (or similar) comment before it's merged.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-08-31

Note: Issues are disabled on this repo, so this review is posted directly on each of the 6 currently-open Dependabot PRs instead of a shared tracking issue. Nothing has been merged, approved, or closed — this PR will only be merged after an explicit human go-ahead comment on it.

# Package Version Change Bump CI Mergeable Action
#277 nanoid 3.3.11 → 3.3.18 patch 🔴 build-ios failing, other 6 green blocked CI Failing — unchanged
#276 (this PR) postcss (test-projects) 8.5.12 → 8.5.26 patch 🟢 Green (7/7) blocked (no conflict) Auto-merge candidate — unchanged
#275 nanoid (test-projects) 3.3.11 → 3.3.18 patch 🔴 build-ios failing, other 6 green blocked CI Failing, same pattern as #277 — unchanged
#274 undici 7.28.0 → 7.29.0 minor 🔴 All 7 jobs failing blocked CI Failing — security-relevant, needs root cause — unchanged
#273 undici (test-projects) 8.5.0 → 8.10.0 minor 🟢 Green (7/7) still dirty Rebase re-requested this cycle in the correct (non-obfuscated) form — see below
#272 fast-uri (test-projects) 4.1.1 → 4.1.2 patch 🟢 Green (7/7) still dirty Rebase re-requested this cycle in the correct (non-obfuscated) form — see below

Correction on #273/#272: every prior rebase request on those two PRs (2026-08-27, 2026-08-29, 2026-08-30) was posted as ·@·d·ependabot r·ebase — obfuscated with dots, which Dependabot silently ignores. That is almost certainly why they've sat dirty for 4+ days despite "being rebased." Verbatim ·@·d·ependabot r·ebase was just posted on both.

On this PR: unchanged — fully green (7/7), no conflicts, scoped to /test-projects/expo-purchasely-test. Holding for explicit human sign-off per process.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-09-02) is posted on #288 (new host — Issues are disabled on this repo) — covers this PR plus #287, #277, #275, #274, #273, #272. This PR: postcss 8.5.12→8.5.26 (patch, /test-projects/expo-purchasely-test), CI green (7/7), no conflicts — auto-merge candidate. See #288 for the full table — nothing merges without a human go-ahead there.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-09-03

Note: Issues are disabled on this repo, so this review is posted directly on the one currently-open Dependabot PR instead of a shared tracking issue/comment host. Nothing has been merged, approved, or closed — this PR will only be merged after an explicit human go-ahead comment on it.

Big change since 2026-09-02: the other six PRs that were being tracked alongside this one (#287, #277, #275, #274, #273, #272) are all now closed — but benignly, by Dependabot itself, not by any human or by this bot. Dependabot posted "Looks like undici is no longer a dependency, so this is no longer needed" (and equivalent messages) on each, consistent with those dependencies having been removed from the relevant manifests by other changes to main/test-projects. No action was needed or taken on any of them.

This PR (#276): postcss 8.5.12 → 8.5.26 (patch, scoped to /test-projects/expo-purchasely-test). CI green (7/7), mergeable_state: blocked (no conflict) — unchanged from every prior cycle. Clean auto-merge candidate. Still waiting on an explicit "merge #276" (or similar) comment before it's merged.

Unrelated process note (carried over from the Firebase-Extension/support-app tracking issues): this bot discovered today that its ·@·d·ependabot r·ebase comments come back rendered with interpunct-obfuscation (·@·d·ependabot r·ebase) regardless of how the command is typed on submission — the obfuscation happens somewhere in the posting path itself, not in how this bot writes the command, so retrying doesn't help. Doesn't affect this PR (it's never been dirty), but noting it here since #273/#272 sat dirty for days for the same reason before being auto-closed.


Generated by Claude Code

@kherembourg kherembourg closed this Sep 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@kherembourg
kherembourg deleted the dependabot/npm_and_yarn/test-projects/expo-purchasely-test/postcss-8.5.26 branch September 3, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants