Skip to content

chore(deps): bump postcss and next in /apps/web - #94

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/multi-5514c58427
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/apps/web/multi-5514c58427

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown

Bumps postcss and next. These dependencies needed to be updated together.
Updates postcss from 8.5.15 to 8.5.29

Release notes

Sourced from postcss's releases.

8.5.29

8.5.28

  • Fixes types regression.

8.5.27

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

  • Fixed cleaning before for new nodes inserted to Root (by @​MahinAnowar).

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.

... (truncated)

Changelog

Sourced from postcss's changelog.

8.5.29

8.5.28

  • Fixes types regression.

8.5.27

8.5.26

  • Fixed list.split() regression (by @​lazerg).
  • Track symlinks in path protection in source map loading (by @​drengir1).

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

... (truncated)

Commits
  • a7a1f34 Release 8.5.29 version
  • b55a36d Update dependencies
  • 7647a81 Escape </style> in output of non-Root nodes (#2163)
  • 7ac9026 Do not split list.comma() and list.space() on separators inside comments (#2162)
  • ebffa97 Add postcss-smooth-corners plugin
  • 57d6401 Speed up source map cleaning
  • 7e46a03 Speed up parser
  • 7f5c417 Improve </style> protection for the case when beffore nodes have different parts
  • 7ba9051 Fix useless ESLint warning
  • 12b4161 Update dependencies
  • Additional commits viewable in compare view
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.


Updates next from 16.2.6 to 16.4.0

Release notes

Sourced from next's releases.

v16.4.0

Check out the 16.4 announcement post to get an overview of the changes.

Core Changes

  • Show compiler plugin warning in more situations: #75682
  • fix(scripts): correct typo in rm.mjs error message: #87015
  • docs: improve clarity and punctuation in README: #86096
  • Fix debug build paths Pages Router support entries: #93529
  • bundle-analyzer: record historical snapshots on each analyze run: #93520
  • fix: detect proxy.ts correctly with compound pageExtensions: #93246
  • feat(turbopack): support false values for resolveAlias config: #93331

Misc Changes

  • docs: correction to dynamicParams migration: #96624
  • docs: proxy event argument: #96435
  • docs: remove experimental note from runtime prefetching: #96615
  • Preserve per-segment prefetching after dynamic navigation: #96583
  • Rename static generation stream option to waitForAllReady: #96564
  • Remove obsolete static generation plumbing: #96563
  • [turbopack] Drop dead writes to exports: #96381
  • [turbopack] Ignore writes to exports after a module.exports = {} writes: #96380
  • [turbopack] Add test for sideEffects with optimizePackageImports: #96549
  • [turbopack] Strip leading BOM before parsing CSS: #96678
  • Upgrade React from cbb046ab-20260731 to 7dfc7ccd-20260803: #96550
  • docs: use relative doc links in instant-navigation error pages: #96672
  • Turbopack: terminate failed plugin worker threads: #96592
  • Fix HTML-limited bot matching in prerender bypass rules: #96584
  • [ci] Fix create_release_branch for new repo permissions: #96641
  • test: skip action module instance deploy test: #96629
  • docs: quote the dynamicParams build error in a blockquote: #96633
  • [react-sync] Open pull requests as the bot that authors the commits: #96682
  • [Bench] Fixes for pure Fizz bench: #96771
  • Derive foreground cache revalidation from the consumer: #96731
  • Fix race when navigating Back before hydration: #96252
  • docs: present each Skill as steps in the AI agents guide: #96751
  • Reuse completed cache entries for the rest of a request: #96727
  • Upgrade React from 7dfc7ccd-20260803 to 11eddecd-20260805: #96735
  • Remove WorkStore execution mode: #96674
  • Remove cache revalidation execution mode reads: #96670
  • Separate App Route render and prerender pipelines: #96662
  • Remove App Page execution mode reads: #96660
  • test: fix missing await in css-chunking test: #96725
  • docs (Skills): stop assuming app/ at the root and port 3000: #96696
  • Implement next/font BeforeResolvePlugins as ImportMappingReplacement: #95808
  • Use Tailwind Turbopack loader in create-next-app: #96606
  • docs: instant navigation quick start with an adoption prompt: #96663
  • Separate App Page render and prerender pipelines: #96659
  • Move App Router execution intent to entrypoints: #96640

... (truncated)

Commits
  • e273d5b v16.4.0
  • fdf41d6 [ai-upgrade] discover upgrade models and reasoning efforts from agent CLIs (#...
  • c3e76ad v16.4.0-canary.63
  • 47c6cc8 Document next analyze export in the package bundling guide (#99735)
  • 5b10604 Revert stabilization of forbidden() and unauthorized() (#99734)
  • f3a6f97 Preserve configured output directories during static export (#99507)
  • b22e5a2 Rename skill to next-bundle-optimizer and document its usage (#99731)
  • 74dc549 [turbo-tasks-backend] Clean up task state before publishing execution complet...
  • ccf8c15 v16.4.0-canary.62
  • b8c7c7f Improve static route error guidance (#99724)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [postcss](https://github.com/postcss/postcss) and [next](https://github.com/vercel/next.js). These dependencies needed to be updated together.

Updates `postcss` from 8.5.15 to 8.5.29
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.15...8.5.29)

Updates `next` from 16.2.6 to 16.4.0
- [Release notes](https://github.com/vercel/next.js/releases)
- [Commits](vercel/next.js@v16.2.6...v16.4.0)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.29
  dependency-type: direct:development
- dependency-name: next
  dependency-version: 16.4.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants