Skip to content

Update dependency autoprefixer to v10.5.0#32

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/autoprefixer-10.x-lockfile
Open

Update dependency autoprefixer to v10.5.0#32
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/autoprefixer-10.x-lockfile

Conversation

@renovate

@renovate renovate Bot commented Dec 16, 2025

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
autoprefixer 10.4.2110.5.0 age confidence

Release Notes

postcss/autoprefixer (autoprefixer)

v10.5.0

Compare Source

  • Added mask-position-x and mask-position-y support (by @​toporek).

v10.4.27

Compare Source

  • Removed development key from package.json.

v10.4.26

Compare Source

  • Reduced package size.

v10.4.25

Compare Source

  • Fixed broken gradients on CSS Custom Properties (by @​serger777).

v10.4.24

Compare Source

  • Made Autoprefixer a little faster (by @​Cherry).

v10.4.23

Compare Source

v10.4.22

Compare Source

  • Fixed stretch prefixes on new Can I Use database.
  • Updated fraction.js.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel

vercel Bot commented Dec 16, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
whale-manager Error Error Jun 11, 2026 3:07pm

@socket-security

socket-security Bot commented Dec 16, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @libsql/client-wasm is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@libsql/client-wasm@0.17.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@libsql/client-wasm@0.17.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm @prisma/client is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/@prisma/client@7.8.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@prisma/client@7.8.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm bcryptjs under BSD-3-Clause-HP

License: BSD-3-Clause-HP - The applicable license policy does not permit this license (5) (package/LICENSE)

From: package.jsonnpm/bcryptjs@3.0.3

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/bcryptjs@3.0.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm better-sqlite3 is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/better-sqlite3@12.10.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/better-sqlite3@12.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
License policy violation: npm caniuse-lite under CC-BY-4.0

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (npm metadata)

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (package/package.json)

License: CC-BY-4.0 - The applicable license policy does not permit this license (5) (package/LICENSE)

From: pnpm-lock.yamlnpm/autoprefixer@10.5.0npm/expo-sqlite@56.0.4npm/@op-engineering/op-sqlite@16.2.0npm/caniuse-lite@1.0.30001797

ℹ Read more on: This package | This alert | What is a license policy violation?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Find a package that does not violate your license policy or adjust your policy to allow this package's license.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/caniuse-lite@1.0.30001797. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm drizzle-orm is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: package.jsonnpm/drizzle-orm@0.45.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/drizzle-orm@0.45.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm js-yaml is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/expo-sqlite@56.0.4npm/js-yaml@4.2.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/js-yaml@4.2.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm node-forge is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: pnpm-lock.yamlnpm/expo-sqlite@56.0.4npm/node-forge@1.4.0

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/node-forge@1.4.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from c67927f to 11cb131 Compare December 31, 2025 14:58
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 11cb131 to 582be7a Compare January 8, 2026 17:06
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 582be7a to 5389453 Compare January 19, 2026 15:31
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 5389453 to 73ea6e3 Compare January 23, 2026 20:39
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 73ea6e3 to 63b0e8c Compare January 30, 2026 21:31
@renovate renovate Bot changed the title chore(deps): update dependency autoprefixer to v10.4.23 chore(deps): update dependency autoprefixer to v10.4.24 Jan 30, 2026
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 63b0e8c to dcde95b Compare February 2, 2026 19:58
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from dcde95b to 0c38e8a Compare February 12, 2026 11:53
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 0c38e8a to e7fb534 Compare February 17, 2026 17:36
@renovate renovate Bot changed the title chore(deps): update dependency autoprefixer to v10.4.24 chore(deps): update dependency autoprefixer to v10.4.25 Feb 25, 2026
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from e7fb534 to 66816ce Compare February 25, 2026 19:01
@renovate renovate Bot changed the title chore(deps): update dependency autoprefixer to v10.4.25 chore(deps): update dependency autoprefixer to v10.4.27 Feb 25, 2026
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 66816ce to 01694c3 Compare February 25, 2026 22:11
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 01694c3 to 7df5609 Compare March 5, 2026 15:40
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 7df5609 to 44518ed Compare March 13, 2026 15:01
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 44518ed to 21404a7 Compare April 1, 2026 16:40
@renovate renovate Bot changed the title chore(deps): update dependency autoprefixer to v10.4.27 Update dependency autoprefixer to v10.4.27 Apr 8, 2026
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 21404a7 to a1d0133 Compare April 8, 2026 16:43
@renovate renovate Bot changed the title Update dependency autoprefixer to v10.4.27 Update dependency autoprefixer to v10.5.0 Apr 13, 2026
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from a1d0133 to e044adc Compare April 13, 2026 21:54
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from e044adc to a10799b Compare April 29, 2026 20:50
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from a10799b to fda827e Compare May 12, 2026 09:39
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from fda827e to 8033512 Compare May 18, 2026 09:28
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from 8033512 to d3bc6b2 Compare May 28, 2026 21:12
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from d3bc6b2 to a7c92cb Compare June 1, 2026 20:40
@renovate renovate Bot force-pushed the renovate/autoprefixer-10.x-lockfile branch from a7c92cb to 9190ce6 Compare June 11, 2026 15:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants