Skip to content

Bump cssnano-preset-advanced from 8.0.2 to 8.0.4 - #753

Open
dependabot[bot] wants to merge 1 commit into
Currentfrom
dependabot/npm_and_yarn/cssnano-preset-advanced-8.0.4
Open

Bump cssnano-preset-advanced from 8.0.2 to 8.0.4#753
dependabot[bot] wants to merge 1 commit into
Currentfrom
dependabot/npm_and_yarn/cssnano-preset-advanced-8.0.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026

Copy link
Copy Markdown
Contributor

Bumps cssnano-preset-advanced from 8.0.2 to 8.0.4.

Release notes

Sourced from cssnano-preset-advanced's releases.

v8.0.4

What's Changed

Bug Fixes

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@8.0.3...cssnano@8.0.4

v8.0.3

What's Changed

Bug Fixes

  • postcss-reduce-initial: update initial properties
  • potcss-minify-gradients: handle more than two stops
  • postcss-normalize-whitespace: preserve whitespace in custom prop
  • postcss-normalize-url: ensure trailing slash is preserved

Other Changes

  • packages now define an exports field in package.json. This prevents any file added to the package to automatically be exposed as a possible import. The has been done in a backward compatible way, so you should be able to import every file you did in the previous release.

  • types have also been regenerated with TypeScript 7.

Full Changelog: https://github.com/cssnano/cssnano/compare/cssnano@8.0.2...cssnano@8.0.3

Commits
  • 6b64af9 chore: update types
  • 6a2ed8b Publish cssnano 8.0.4
  • cb09239 fix(postcss-svgo): use built-in URI encoder
  • e1a7419 fix(postcss-svgo): improve character encoding
  • dceffee chore: update lockfile after creating devEngines field in package.json
  • dca50f7 docs: add devengines field to website package.json
  • c169273 docs: remove unused website dependency
  • bca3dad docs: add browserslist query for building the website
  • 67c666e chore: remove unused package.json field
  • c24a5a4 chore(ci): update devTools packageManger and use pnpm/setup everywhere
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [cssnano-preset-advanced](https://github.com/cssnano/cssnano) from 8.0.2 to 8.0.4.
- [Release notes](https://github.com/cssnano/cssnano/releases)
- [Commits](https://github.com/cssnano/cssnano/compare/cssnano-preset-advanced@8.0.2...cssnano@8.0.4)

---
updated-dependencies:
- dependency-name: cssnano-preset-advanced
  dependency-version: 8.0.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 10, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​cssnano-preset-advanced@​8.0.2 ⏵ 8.0.4100 +110010097 +1100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Development

Successfully merging this pull request may close these issues.

1 participant