Skip to content

Update @tailwindcss/postcss 4.1.18 → 4.2.2 (minor)#588

Open
depfu[bot] wants to merge 2 commits intomainfrom
depfu/update/npm/@tailwindcss/postcss-4.2.2
Open

Update @tailwindcss/postcss 4.1.18 → 4.2.2 (minor)#588
depfu[bot] wants to merge 2 commits intomainfrom
depfu/update/npm/@tailwindcss/postcss-4.2.2

Conversation

@depfu
Copy link
Copy Markdown
Contributor

@depfu depfu bot commented Mar 19, 2026

Here is everything you need to know about this update. Please take a good look at what changed and the test results before merging this pull request.

What changed?

✳️ @​tailwindcss/postcss (4.1.18 → 4.2.2)

Sorry, we couldn't find anything useful about this release.

↗️ @​emnapi/core (indirect, 1.7.1 → 1.8.1) · Repo

Release Notes

1.8.1

What's Changed

Full Changelog: v1.8.0...v1.8.1

1.8.0

What's Changed

Full Changelog: v1.7.1...v1.8.0

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ @​emnapi/runtime (indirect, 1.7.1 → 1.8.1) · Repo

Release Notes

1.8.1

What's Changed

Full Changelog: v1.8.0...v1.8.1

1.8.0

What's Changed

Full Changelog: v1.7.1...v1.8.0

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ @​napi-rs/wasm-runtime (indirect, 1.1.0 → 1.1.1) · Repo

Sorry, we couldn't find anything useful about this release.

↗️ enhanced-resolve (indirect, 5.18.4 → 5.20.1) · Repo

Release Notes

5.20.1

Patch Changes

5.20.0

Features

  • Added the baseUrl option to override the tsconfig.json's baseUrl
  • Enabled trailing commas support for JSONC

Fixes

  • Detect circular extends to prevent infinite loop in tsconfig.json
  • Support JSONC comments in tsconfig.json

5.19.0

Features

  • Added TsconfigPathsPlugin (replacement for tsconfig-paths-webpack-plugin) .

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-darwin-arm64 (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-darwin-x64 (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-linux-arm64-gnu (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-linux-arm64-musl (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-linux-x64-gnu (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-linux-x64-musl (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

↗️ lightningcss-win32-x64-msvc (indirect, 1.30.2 → 1.32.0) · Repo

Release Notes

1.32.0

Added

Fixed

1.31.0

Features

Fixes

Does any of this look wrong? Please let us know.

Commits

See the full diff on Github. The new version differs by more commits than we can show here.

🆕 tailwindcss (added, 4.2.2)

🗑️ tailwindcss (removed)

🗑️ tailwindcss (removed)


Depfu Status

Depfu will automatically keep this PR conflict-free, as long as you don't add any commits to this branch yourself. You can also trigger a rebase manually by commenting with @depfu rebase.

All Depfu comment commands
@​depfu rebase
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu cancel merge
Cancels automatic merging of this PR
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Ignores all future updates for this dependency and closes this PR
@​depfu pause [minor|major]
Ignores all future minor/major updates for this dependency and closes this PR
@​depfu resume
Future versions of this dependency will create PRs again (leaves this PR as is)

@depfu depfu bot added the depfu label Mar 19, 2026
@code-genius-code-coverage
Copy link
Copy Markdown

The files' contents are under analysis for test generation.

@github-actions github-actions bot added the size/L Denotes a PR that changes 100-499 lines, ignoring generated files. label Mar 19, 2026
@deepsource-io
Copy link
Copy Markdown

deepsource-io bot commented Mar 19, 2026

DeepSource Code Review

We reviewed changes in 00693a2...0231cd8 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Coverage  

Code Review Summary

Analyzer Status Updated (UTC) Details
Test coverage Mar 19, 2026 6:25p.m. Review ↗
Secrets Mar 19, 2026 6:25p.m. Review ↗
JavaScript Mar 19, 2026 6:25p.m. Review ↗

Code Coverage Summary

Language Line Coverage (Overall)
Aggregate
93.8%
Javascript
93.8%

➟ Additional coverage metrics may have been reported. See full coverage report ↗

@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 19, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedtailwindcss@​4.2.1 ⏵ 4.2.2100 +110084 +198100
Updated@​tailwindcss/​postcss@​4.1.18 ⏵ 4.2.2100 +110010098100

View full report

@guibranco guibranco enabled auto-merge (squash) March 19, 2026 17:26
@gstraccini gstraccini bot added the ☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) label Mar 19, 2026
@socket-security
Copy link
Copy Markdown

socket-security bot commented Mar 19, 2026

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Block Low
Potential code anomaly (AI signal): npm @tailwindcss/oxide-wasm32-wasi is 90.0% likely to have a medium risk anomaly

Notes: The file itself does not contain overt malicious code (no network calls, no obfuscated payloads, no hardcoded credentials). However, it deliberately exposes powerful capabilities to loaded WASM modules and local scripts: it passes all environment variables into WASI and preopens the filesystem root, and it implements importScripts by reading and eval-ing local files. These choices make the environment capable of data theft or system access if untrusted wasm or scripts are executed. Treat wasm modules and files loaded via importScripts as fully trusted/native — do not run untrusted modules with this loader. Recommend restricting WASI preopens to a minimal directory and avoid passing full process.env, and avoid eval-based importScripts when possible.

Confidence: 0.90

Severity: 0.60

From: package-lock.jsonnpm/@tailwindcss/postcss@4.2.2npm/@tailwindcss/oxide-wasm32-wasi@4.2.2

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@tailwindcss/oxide-wasm32-wasi@4.2.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Copy link
Copy Markdown
Member

@guibranco guibranco left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved by gstraccini[bot]

@gstraccini gstraccini bot added the 🤖 bot Automated processes or integrations label Mar 19, 2026
Copy link
Copy Markdown
Member

@guibranco guibranco left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automatically approved by gstraccini[bot]

@guibranco
Copy link
Copy Markdown
Member

@depfu merge

@github-actions
Copy link
Copy Markdown

Infisical secrets check: ✅ No secrets leaked!

💻 Scan logs
2026-03-19T18:25:49Z INF scanning for exposed secrets...
6:25PM INF 482 commits scanned.
2026-03-19T18:25:49Z INF scan completed in 378ms
2026-03-19T18:25:49Z INF no leaks found

@sonarqubecloud
Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

☑️ auto-merge Automatic merging of pull requests (gstraccini-bot) 🤖 bot Automated processes or integrations depfu size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant