Skip to content

chore(deps): Bump postcss-selector-parser, @nextcloud/eslint-config, postcss-modules-local-by-default and postcss-modules-scope - #6171

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0c95733375
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-0c95733375

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps postcss-selector-parser to 7.1.6 and updates ancestor dependencies postcss-selector-parser, @nextcloud/eslint-config, postcss-modules-local-by-default and postcss-modules-scope. These dependencies need to be updated together.

Updates postcss-selector-parser from 6.1.4 to 7.1.6

Release notes

Sourced from postcss-selector-parser's releases.

7.1.6

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)

7.1.5

  • fix: don't treat a non-prefix token before | as a namespace (#324 by @​spokodev)
  • fix: preserve whitespace before a * namespace in attribute selectors (#325 by @​spokodev)
  • fix: TypeError on unclosed [, ( and trailing | (#330 by @​theRizwan)

7.1.4

  • fix: tolerate non-node children when serializing selectors

7.1.3

  • Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)

7.1.2

v7.1.1

7.1.1

  • perf: replace startsWith with strict equality (#308)
  • fix(types): add walkUniversal declaration (#311)

v7.1.0

7.1.0

  • feat: insert(Before|After) support multiple new node

v7.0.0

7.0.0

  • Feat: make insertions during iteration safe (major)
Changelog

Sourced from postcss-selector-parser's changelog.

7.1.6 - 2026-09-03

  • fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability (GHSA-rj75-hqrm-r3gf, reported by Wayde Shi)

7.1.5 - 2026-08-07

  • fix: don't treat a non-prefix token before | as a namespace (#324 by @​spokodev)
  • fix: preserve whitespace before a * namespace in attribute selectors (#325 by @​spokodev)
  • fix: TypeError on unclosed [, ( and trailing | (#330 by @​theRizwan)

7.1.4 - 2026-06-11

  • fix: tolerate non-node children when serializing selectors

7.1.3 - 2026-06-11

  • Improve fix CVE-2026-9358 (NVD) / SNYK-JS-POSTCSSSELECTORPARSER-16873882 (clone/walk)

7.1.2 - 2026-06-09

7.1.1

  • perf: replace startsWith with strict equality (#308)
  • fix(types): add walkUniversal declaration (#311)

7.1.0

  • feat: insert(Before|After) support multiple new node

7.0.0

  • Feat: make insertions during iteration safe (major)

6.1.2

  • Fixed: erroneous trailing combinators in pseudos

6.1.1

  • Fixed: improve typings of constructor helpers (#292)

6.1.0

  • Feature: add sourceIndex to Selector nodes (#290)

6.0.16

... (truncated)

Commits
  • 4eb3468 7.1.6
  • 62b1917 fix: parse flat selectors in linear time, closing a CPU exhaustion vulnerability
  • e33e9bc 7.1.5
  • 6f4e6c1 fix: TypeError on unclosed [, ( and trailing | (#330)
  • 4d8437f fix: preserve whitespace before a * namespace in attribute selectors (#325)
  • e2f9029 fix: don't treat a non-prefix token before | as a namespace (#324)
  • dd50ee1 chore(deps-dev): bump postcss from 8.5.18 to 8.5.23 (#331)
  • 7e3abb2 chore(deps-dev): bump postcss from 8.5.15 to 8.5.18 (#328)
  • See full diff in compare view
Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Updates @nextcloud/eslint-config from 8.4.2 to 9.0.1

Release notes

Sourced from @​nextcloud/eslint-config's releases.

v9.0.1

v9.0.1 (2026-07-07)

Fixed

  • fix(vue): error on vue/attributes-order and vue/order-in-components instead of warn #1445 (susnux)
  • fix: no-deprecated-library-* rules incorrectly behave for nextcloud/vue syntax #1452 (Antreesy)
  • fix(no-deprecated-library-props): support win32 filesystem and different @nextcloud/vue directory structures #1454 (ShGKme)
  • fix(no-deprecated-library-props): support camelCase attributes #1453 (Antreesy)
  • fix: increase min. Node version to 22.14 #1455 (susnux)

v9.0.0

v9.0.0 (2026-06-26)

Breaking

This package now is using ESLint v10 and requires ESLint flat configurations. Please refer to the README on how to adjust your configuration for flat config.

Potential pitfalls

Some of the used eslint plugins still keep a ESLint v8 compatibility, this can cause some issues if not all packages are updated to the ESLint v10 compatible version.

If you see a linter error like the one below make sure to update all nested dependencies, either using the sledge hammer method (remove the lock file and run npm i) or by running npm update.

TypeError: scopeManager.addGlobals is not a function

Added

  • feat: migrate to ESLint v10 #1323 (susnux)
  • feat: new modular config for (and with) ESLint v9 support #887
  • feat: merge plugin repository #899
  • feat: enforce non-breaking spaces before ellipsis for translations #948
  • feat: add special config for libraries #949
  • feat: add import and export rules #981
  • feat: introduce @​nextcloud/vue eslint plugin #939
  • feat(codeStyle): enforce top-level-function #1033 (ShGKme)
  • feat(nextcloud-vue): add rule for deprecated NcButton props #1045 (susnux)
  • feat(vue): add vue/no-useless-v-bind rule #1063 (susnux)
  • feat(vue): add vue/prefer-separate-static-class rule #1065 (susnux)
  • feat(vue3): add script-setup releated rules #1064 (susnux)
  • feat(no-deprecated-props): extend existing rules to support other components #1069 (Antreesy)
  • feat(imports): add custom plugin to suggest file extensions #1110 (susnux)
  • feat(filesystem): ignore all files within the .gitignore #1108 (susnux)
  • feat(l10n-plugin): also handle vue templates #1113 (susnux)
  • feat(nextcloud-vue-plugin): deprecate additional props #1163 (Antreesy)
  • feat(nextcloud-vue-plugin): deprecate additional exports #1162 (Antreesy)
  • feat(nextcloud-vue-plugin): deprecate NcPopover props #1165 (Antreesy)
  • feat(vue): add vue/component-options-name-casing with PascalCase #1261 (ShGKme)
  • feat(vue3): force camelCase for events in <script> #1262 (ShGKme)
  • feat(vue3): force camelCase for events in \<template> #1263 (ShGKme)
  • feat(vue3): force camelCase for slot names #1264 (ShGKme)
  • feat(vue3): force camelCase for props in template #1266 (ShGKme)

... (truncated)

Changelog

Sourced from @​nextcloud/eslint-config's changelog.

v9.0.1 (2026-07-07)

Fixed

  • fix(vue): error on vue/attributes-order and vue/order-in-components instead of warn #1445 (susnux)
  • fix: no-deprecated-library-* rules incorrectly behave for nextcloud/vue syntax #1452 (Antreesy)
  • fix(no-deprecated-library-props): support win32 filesystem and different @nextcloud/vue directory structures #1454 (ShGKme)
  • fix(no-deprecated-library-props): support camelCase attributes #1453 (Antreesy)
  • fix: increase min. Node version to 22.14 #1455 (susnux)

v9.0.0 (2026-06-26)

Breaking

This package now is using ESLint v10 and requires ESLint flat configurations. Please refer to the README on how to adjust your configuration for flat config.

Potential pitfalls

Some of the used eslint plugins still keep a ESLint v8 compatibility, this can cause some issues if not all packages are updated to the ESLint v10 compatible version.

If you see a linter error like the one below make sure to update all nested dependencies, either using the sledge hammer method (remove the lock file and run npm i) or by running npm update.

TypeError: scopeManager.addGlobals is not a function

Added

  • feat: migrate to ESLint v10 #1323 (susnux)
  • feat: new modular config for (and with) ESLint v9 support #887
  • feat: merge plugin repository #899
  • feat: enforce non-breaking spaces before ellipsis for translations #948
  • feat: add special config for libraries #949
  • feat: add import and export rules #981
  • feat: introduce @​nextcloud/vue eslint plugin #939
  • feat(codeStyle): enforce top-level-function #1033 (ShGKme)
  • feat(nextcloud-vue): add rule for deprecated NcButton props #1045 (susnux)
  • feat(vue): add vue/no-useless-v-bind rule #1063 (susnux)
  • feat(vue): add vue/prefer-separate-static-class rule #1065 (susnux)
  • feat(vue3): add script-setup releated rules #1064 (susnux)
  • feat(no-deprecated-props): extend existing rules to support other components #1069 (Antreesy)
  • feat(imports): add custom plugin to suggest file extensions #1110 (susnux)
  • feat(filesystem): ignore all files within the .gitignore #1108 (susnux)
  • feat(l10n-plugin): also handle vue templates #1113 (susnux)
  • feat(nextcloud-vue-plugin): deprecate additional props #1163 (Antreesy)
  • feat(nextcloud-vue-plugin): deprecate additional exports #1162 (Antreesy)
  • feat(nextcloud-vue-plugin): deprecate NcPopover props #1165 (Antreesy)
  • feat(vue): add vue/component-options-name-casing with PascalCase #1261 (ShGKme)
  • feat(vue3): force camelCase for events in <script> #1262 (ShGKme)
  • feat(vue3): force camelCase for events in \<template> #1263 (ShGKme)
  • feat(vue3): force camelCase for slot names #1264 (ShGKme)
  • feat(vue3): force camelCase for props in template #1266 (ShGKme)
  • feat(import): enforce consistent types imports and ban usage of inline type specifiers #1382 (susnux)

Fixed

... (truncated)

Commits
  • 660197b Merge pull request #1456 from nextcloud-libraries/chore/v901
  • f466ba3 chore: prepare v9.0.1
  • 3755602 Merge pull request #1455 from nextcloud-libraries/fix/reg-node
  • c3e12f3 Merge pull request #1453 from nextcloud-libraries/fix/1001/adjust-rules-camel...
  • 282d890 fix: support camelCase attributes for deprecations
  • 6e88372 fix: increase min. Node version to 22.14
  • 4f469a3 Merge pull request #1454 from nextcloud-libraries/fix/find-package-json-lib
  • 1662e34 fix(no-deprecated-library-props): support win32 fs
  • 0e56404 Merge pull request #1447 from nextcloud-libraries/dependabot/npm_and_yarn/esl...
  • 60bb082 Merge pull request #1452 from nextcloud-libraries/fix/1001/adjust-rules
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for @​nextcloud/eslint-config since your current version.


Updates postcss-modules-local-by-default from 4.0.5 to 4.2.0

Release notes

Sourced from postcss-modules-local-by-default's releases.

v4.2.0

4.2.0 - 2024-12-11

  • feat: add support a /* cssmodules-pure-no-check */ comment

v4.1.0

4.1.0 - 2024-11-11

  • feat: add global() and local() for animations
  • feat: add pure ignore comment
  • fix: css nesting and pure mode
Changelog

Sourced from postcss-modules-local-by-default's changelog.

4.2.0 - 2024-12-11

  • feat: add support a /* cssmodules-pure-no-check */ comment

4.1.0 - 2024-11-11

  • feat: add global() and local() for animations
  • feat: add pure ignore comment
  • fix: css nesting and pure mode
Commits
  • db195e7 chore(release): 4.2.0
  • ba7e8ef feat: added support a cssmodules-pure-no-check comment
  • 39a2f78 docs: fix (#83)
  • e489ff8 chore(release): 4.1.0
  • 3811927 fix: css nesting and pure mode
  • 582bd9e chore: postcss-selector-parser (#81)
  • 9d07eeb feat: add pure ignore comment for CSS Modules (#80)
  • fde62d7 feat: add global and local for animations (#76)
  • a73b700 test: for current pure logic (#74)
  • f1c05a5 test: enhanced test cases to prepare for CSS declaration-level processing (#77)
  • See full diff in compare view

Updates postcss-modules-scope from 3.2.0 to 3.2.1

Release notes

Sourced from postcss-modules-scope's releases.

v3.2.1

3.2.1

Chore

  • update postcss-selector-parser
Changelog

Sourced from postcss-modules-scope's changelog.

3.2.1

Chore

  • update postcss-selector-parser
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

…postcss-modules-local-by-default and postcss-modules-scope

Bumps [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser) to 7.1.6 and updates ancestor dependencies [postcss-selector-parser](https://github.com/postcss/postcss-selector-parser), [@nextcloud/eslint-config](https://github.com/nextcloud-libraries/eslint-config), [postcss-modules-local-by-default](https://github.com/css-modules/postcss-modules-local-by-default) and [postcss-modules-scope](https://github.com/css-modules/postcss-modules-scope). These dependencies need to be updated together.


Updates `postcss-selector-parser` from 6.1.4 to 7.1.6
- [Release notes](https://github.com/postcss/postcss-selector-parser/releases)
- [Changelog](https://github.com/postcss/postcss-selector-parser/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss-selector-parser@6.1.4...7.1.6)

Updates `@nextcloud/eslint-config` from 8.4.2 to 9.0.1
- [Release notes](https://github.com/nextcloud-libraries/eslint-config/releases)
- [Changelog](https://github.com/nextcloud-libraries/eslint-config/blob/main/CHANGELOG.md)
- [Commits](nextcloud-libraries/eslint-config@v8.4.2...v9.0.1)

Updates `postcss-modules-local-by-default` from 4.0.5 to 4.2.0
- [Release notes](https://github.com/css-modules/postcss-modules-local-by-default/releases)
- [Changelog](https://github.com/css-modules/postcss-modules-local-by-default/blob/master/CHANGELOG.md)
- [Commits](css-modules/postcss-modules-local-by-default@v4.0.5...v4.2.0)

Updates `postcss-modules-scope` from 3.2.0 to 3.2.1
- [Release notes](https://github.com/css-modules/postcss-modules-scope/releases)
- [Changelog](https://github.com/css-modules/postcss-modules-scope/blob/master/CHANGELOG.md)
- [Commits](css-modules/postcss-modules-scope@v3.2.0...v3.2.1)

---
updated-dependencies:
- dependency-name: postcss-selector-parser
  dependency-version: 7.1.6
  dependency-type: indirect
- dependency-name: "@nextcloud/eslint-config"
  dependency-version: 9.0.1
  dependency-type: direct:development
- dependency-name: postcss-modules-local-by-default
  dependency-version: 4.2.0
  dependency-type: indirect
- dependency-name: postcss-modules-scope
  dependency-version: 3.2.1
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from elzody as a code owner October 8, 2026 08:57
@dependabot dependabot Bot added 3. to review Ready to be reviewed dependencies Pull requests that update a dependency file labels Oct 8, 2026
@dependabot
dependabot Bot requested a review from juliusknorr as a code owner October 8, 2026 08:57
@dependabot dependabot Bot added 3. to review Ready to be reviewed dependencies Pull requests that update a dependency file labels Oct 8, 2026
@github-actions
github-actions Bot enabled auto-merge October 8, 2026 08:57
@elzody

elzody commented Oct 8, 2026

Copy link
Copy Markdown
Collaborator

Gonna close this for now until we sort out #6173.

@elzody elzody closed this Oct 8, 2026
auto-merge was automatically disabled October 8, 2026 21:49

Pull request was closed

@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/multi-0c95733375 branch October 8, 2026 21:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review Ready to be reviewed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant