Skip to content

chore(deps): update dependency @tailwindcss/postcss (main)#7

Open
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-tailwindcss-postcss-4.1.x-lockfile
Open

chore(deps): update dependency @tailwindcss/postcss (main)#7
mend-for-github-com[bot] wants to merge 1 commit intomainfrom
whitesource-remediate/main-tailwindcss-postcss-4.1.x-lockfile

Conversation

@mend-for-github-com
Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@tailwindcss/postcss (source) 4.1.114.1.12 age adoption passing confidence
@tailwindcss/postcss (source) 4.1.144.1.15 age adoption passing confidence

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score Vulnerability Reachability
High High 8.8 CVE-2026-23950

Unreachable

High High 8.2 CVE-2026-24842

Unreachable

High High 7.1 CVE-2026-26960

Unreachable


Release Notes

tailwindlabs/tailwindcss (@​tailwindcss/postcss)

v4.1.12

Compare Source

Fixed
  • Don't consider the global important state in @apply (#​18404)
  • Add missing suggestions for flex-<number> utilities (#​18642)
  • Fix trailing ) from interfering with extraction in Clojure keywords (#​18345)
  • Detect classes inside Elixir charlist, word list, and string sigils (#​18432)
  • Track source locations through @plugin and @config (#​18345)
  • Allow boolean values of process.env.DEBUG in @tailwindcss/node (#​18485)
  • Ignore consecutive semicolons in the CSS parser (#​18532)
  • Center the dropdown icon added to an input with a paired datalist by default (#​18511)
  • Extract candidates in Slang templates (#​18565)
  • Improve error messages when encountering invalid functional utility names (#​18568)
  • Discard CSS AST objects with false or undefined properties (#​18571)
  • Allow users to disable URL rebasing in @tailwindcss/postcss via transformAssetUrls: false (#​18321)
  • Fix false-positive migrations in addEventListener and JavaScript variable names (#​18718)
  • Fix Standalone CLI showing default Bun help when run via symlink on Windows (#​18723)
  • Read from --border-color-* theme keys in divide-* utilities for backwards compatibility (#​18704)
  • Don't scan .hdr and .exr files for classes by default (#​18734)

  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants