Skip to content

fix: override postcss-selector-parser to 7.1.6 for GHSA-rj75-hqrm-r3gf - #119

Merged
arodiss merged 1 commit into
mainfrom
fix/postcss-selector-parser-cve
Oct 6, 2026
Merged

arodiss merged 1 commit into
mainfrom
fix/postcss-selector-parser-cve

Conversation

@arodiss

@arodiss arodiss commented Oct 6, 2026 •

Copy link
Copy Markdown

Summary

Fixes Dependabot alert #41 (GHSA-rj75-hqrm-r3gf, medium): parsing a long flat selector in postcss-selector-parser < 7.1.6 takes quadratic time, so a large enough one can exhaust the CPU.

The vulnerable copies came in only through packages/web:

  • @tailwindcss/typography@0.5.20 pins exactly 6.0.10
  • tailwindcss@3.4.19 and postcss-nested@6.2.0 require ^6.1.2 (resolved to 6.1.4)

The fix exists only in 7.1.6, with no 6.x backport. That's why Dependabot couldn't open a fix PR (its own update run failed).

Changes

  • Root package.json: add the "postcss-selector-parser": "^7.1.6" override, next to the existing security overrides.
  • packages/web/package.json: move @tailwindcss/typography to devDependencies. It only runs when Tailwind builds the CSS, so it isn't a runtime dependency, and Dependabot was wrongly labelling the alert as "runtime".
  • package-lock.json: edited by hand. One top-level postcss-selector-parser@7.1.6 entry replaces the three 6.x copies. I didn't regenerate the lockfile because main's lockfile has already drifted from what npm 11 writes: npm install --package-lock-only on a clean main produces about 600 lines of unrelated churn. That cleanup belongs in a separate PR.

Risk

The vulnerability isn't actually exploitable here. Tailwind only parses our own CSS and class names, and only at build time. This PR still clears the alert.

The only breaking change in 7.0.0 is that inserting nodes while walking a selector is now safe. The rest of the API Tailwind 3 uses is the same.

Verification

  • npm ci succeeds with the edited lockfile, and npm ls postcss-selector-parser shows 7.1.6 everywhere it appears (deduped).
  • I compiled packages/web/src/app/globals.css through the project's PostCSS pipeline (tailwindcss + autoprefixer, with the real tailwind.config.ts) before and after the change. The output is byte-identical (99,270 bytes).
  • npm run build -w @open-inspect/web succeeds.
  • npm test -w @open-inspect/web: 367 tests fail locally both on main and on this branch. The causes are local Node 26 environment problems (undefined localStorage, timeouts), so this change doesn't affect the tests. CI is the source of truth.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • This update includes behind-the-scenes project maintenance. No changes to the app’s features or behavior are visible to end users.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Team
  • Run ID: 6b2486a8-986f-46ae-975d-f6796d154fcb
📥 Commits

Reviewing files that changed from the base of the PR and between 6808370 and 095a6b5.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (2)
  • package.json
  • packages/web/package.json
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Terraform Validation Results

Validation job: success
Check Secrets job: success

Step Status
Format Success
Init Success
Validate Success
Tests Success
Modal module tests Success

Pushed by: @arodiss, Action: pull_request

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Terraform Plan Results

Status: Success

Show Plan
terraform_data.access_control_gate: Refreshing state... [id=2b965617-b42b-4b42-5ea5-a1c3c05f10be]
terraform_data.cloudflare_custom_domain_gate: Refreshing state... [id=09b89c9b-996a-d28b-1f9c-08760a492dac]
terraform_data.sign_in_provider_gate: Refreshing state... [id=b29a3d55-0be5-fb92-10a9-027df10c4b75]
local_file.web_app_wrangler_production[0]: Refreshing state... [id=d58ccd8dd2962c70f7cff2ffac9821e9e711af31]
null_resource.github_bot_build[0]: Refreshing state... [id=1569982186601318620]
null_resource.control_plane_build: Refreshing state... [id=7089745774138212655]
null_resource.slack_bot_build[0]: Refreshing state... [id=930192839021357569]
module.modal_app[0].null_resource.modal_secrets[0]: Refreshing state... [id=4371755998621267773]
null_resource.web_app_cloudflare_build[0]: Refreshing state... [id=7439365487219316726]
random_password.service_auth_secret_web: Refreshing state... [id=none]
random_bytes.provider_accounts_encryption_key: Refreshing state...
random_password.image_callback_token_pepper: Refreshing state... [id=none]
data.external.modal_source_hash[0]: Reading...
null_resource.linear_bot_build[0]: Refreshing state... [id=7970927320763146623]
random_password.service_auth_secret_linear_bot: Refreshing state... [id=none]
random_password.service_auth_secret_github_bot: Refreshing state... [id=none]
random_password.service_auth_secret_slack_bot: Refreshing state... [id=none]
module.session_index_kv.cloudflare_workers_kv_namespace.this: Refreshing state... [id=ea0a253d5cb64d75a841acb88040cd2f]
cloudflare_queue.image_build_finalization: Refreshing state... [id=a0647323f7424e778b9d59da50dc55cf]
cloudflare_queue.slack_completion_delivery[0]: Refreshing state... [id=247b1100bac2408684d6a75c1bca0d28]
cloudflare_queue.slack_completion_delivery_dlq[0]: Refreshing state... [id=396865e4939b4160937b2dc9ad5dabe1]
cloudflare_queue.github_autofix_dlq[0]: Refreshing state... [id=3a27213aeba149d4b7cbf2d3551842f8]
cloudflare_queue.github_autofix[0]: Refreshing state... [id=033a23f13783415385b2f8799416c20f]
cloudflare_queue.image_build_finalization_dlq: Refreshing state... [id=61535c686d8546099cfddcf39833572b]
cloudflare_r2_bucket.media: Refreshing state... [id=open-inspect-media-codos]
module.slack_kv[0].cloudflare_workers_kv_namespace.this: Refreshing state... [id=ab5c371c8bc04a938ff2f71809933aa0]
data.external.modal_source_hash[0]: Read complete after 1s [id=-]
module.linear_kv[0].cloudflare_workers_kv_namespace.this: Refreshing state... [id=777f94c3595f4de680c256a4e5fc6653]
module.github_kv[0].cloudflare_workers_kv_namespace.this: Refreshing state... [id=e0848d433a4f466cafd4ed5d140aad7d]
cloudflare_d1_database.main: Refreshing state... [id=f747a908-5c69-45a1-86ab-ceb5250cf5e0]
module.modal_app[0].null_resource.modal_deploy: Refreshing state... [id=1275138313859208814]
module.slack_bot_worker[0].cloudflare_worker.this: Refreshing state... [id=375c2c6875904657bce05c62c8048c76]
module.linear_bot_worker[0].cloudflare_worker.this: Refreshing state... [id=049cd48117bc48b9b4332683a97d0a0e]
module.slack_bot_worker[0].cloudflare_worker_version.this: Refreshing state... [id=02b945c7-5554-4947-b52e-2a26a776293e]
module.linear_bot_worker[0].cloudflare_worker_version.this: Refreshing state... [id=d509693d-eb64-4cce-b532-aad8c0738381]
null_resource.d1_migrations: Refreshing state... [id=4427310787733614608]
module.slack_bot_worker[0].cloudflare_workers_deployment.this: Refreshing state... [id=5c21807a-3498-43ad-b1e6-829e1420180d]
module.linear_bot_worker[0].cloudflare_workers_deployment.this: Refreshing state... [id=2509595a-aae1-43d1-8716-41a095e0fe03]
module.control_plane_worker.cloudflare_worker.this: Refreshing state... [id=3457352971a74b89be5ed3700db48a8e]
cloudflare_queue_consumer.slack_completion_delivery[0]: Refreshing state...
module.control_plane_worker.cloudflare_worker_version.this: Refreshing state... [id=9785b074-8fba-423f-b2b4-9a244414f9b4]
module.control_plane_worker.cloudflare_workers_deployment.this: Refreshing state... [id=b908a483-04e8-45b8-9b2b-603ebe856240]
module.control_plane_worker.cloudflare_workers_cron_trigger.this[0]: Refreshing state... [id=open-inspect-control-plane-codos]
null_resource.web_app_cloudflare_deploy[0]: Refreshing state... [id=7624399261610026232]
cloudflare_queue_consumer.image_build_finalization: Refreshing state...
module.github_bot_worker[0].cloudflare_worker.this: Refreshing state... [id=fa832fd890a14336bc3c63305e9bc36f]
null_resource.web_app_cloudflare_secrets[0]: Refreshing state... [id=8981633407656564074]
module.github_bot_worker[0].cloudflare_worker_version.this: Refreshing state... [id=eb5355ec-15a8-4fdb-9f6d-bbdda7317b2d]
module.github_bot_worker[0].cloudflare_workers_deployment.this: Refreshing state... [id=b43a0548-e260-44da-8a70-d19ecf7cefce]
cloudflare_queue_consumer.github_autofix[0]: Refreshing state...

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  + create
  ~ update in-place
-/+ destroy and then create replacement

Terraform will perform the following actions:

  # local_file.web_app_wrangler_production[0] will be created
  + resource "local_file" "web_app_wrangler_production" {
      + content              = <<-EOT
            name = "open-inspect-web-codos"
            main = ".open-next/worker.js"
            compatibility_date = "2025-08-15"
            compatibility_flags = ["nodejs_compat", "global_fetch_strictly_public"]
            # Keep-names makes esbuild emit __name() calls, which leak into next-themes'
            # inline script and throw in the browser.
            keep_names = false
            
            # A custom-domain deployment has one canonical browser origin.
            workers_dev = true
            
            [vars]
            CONTROL_PLANE_URL = "https://open-inspect-control-plane-codos.opencodos.workers.dev"
            NEXT_PUBLIC_WS_URL = "wss://open-inspect-control-plane-codos.opencodos.workers.dev"
            NEXT_PUBLIC_SANDBOX_PROVIDER = "modal"
            NEXT_PUBLIC_APP_NAME = "Open-Inspect"
            NEXT_PUBLIC_APP_ICON_URL = ""
            
            [assets]
            directory = ".open-next/assets"
            binding = "ASSETS"
            
            [[services]]
            binding = "CONTROL_PLANE_WORKER"
            service = "open-inspect-control-plane-codos"
        EOT
      + content_base64sha256 = (known after apply)
      + content_base64sha512 = (known after apply)
      + content_md5          = (known after apply)
      + content_sha1         = (known after apply)
      + content_sha256       = (known after apply)
      + content_sha512       = (known after apply)
      + directory_permission = "0777"
      + file_permission      = "0777"
      + filename             = "../../..//packages/web/wrangler.production.toml"
      + id                   = (known after apply)
    }

  # null_resource.control_plane_build must be replaced
-/+ resource "null_resource" "control_plane_build" {
      ~ id       = "7089745774138212655" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:33:10Z" -> (known after apply)
        }
    }

  # null_resource.github_bot_build[0] must be replaced
-/+ resource "null_resource" "github_bot_build" {
      ~ id       = "1569982186601318620" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:33:10Z" -> (known after apply)
        }
    }

  # null_resource.linear_bot_build[0] must be replaced
-/+ resource "null_resource" "linear_bot_build" {
      ~ id       = "7970927320763146623" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:33:10Z" -> (known after apply)
        }
    }

  # null_resource.slack_bot_build[0] must be replaced
-/+ resource "null_resource" "slack_bot_build" {
      ~ id       = "930192839021357569" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:33:10Z" -> (known after apply)
        }
    }

  # null_resource.web_app_cloudflare_build[0] must be replaced
-/+ resource "null_resource" "web_app_cloudflare_build" {
      ~ id       = "7439365487219316726" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:33:10Z" -> (known after apply)
        }
    }

  # null_resource.web_app_cloudflare_deploy[0] must be replaced
-/+ resource "null_resource" "web_app_cloudflare_deploy" {
      ~ id       = "7624399261610026232" -> (known after apply)
      ~ triggers = { # forces replacement
          ~ "always_run" = "2026-10-05T23:36:03Z" -> (known after apply)
        }
    }

  # module.control_plane_worker.cloudflare_worker.this will be updated in-place
  ~ resource "cloudflare_worker" "this" {
        id             = "3457352971a74b89be5ed3700db48a8e"
        name           = "open-inspect-control-plane-codos"
      ~ observability  = {
          ~ logs               = {
              + destinations       = (known after apply)
                # (4 unchanged attributes hidden)
            }
          ~ traces             = {
              + destinations       = (known after apply)
                # (3 unchanged attributes hidden)
            }
            # (2 unchanged attributes hidden)
        }
      ~ references     = {
          ~ dispatch_namespace_outbounds = [] -> (known after apply)
          ~ domains                      = [] -> (known after apply)
          ~ durable_objects              = [
              - {
                  - namespace_id   = "34735ba6d2804d67a82cf0bdf5a3175f" -> null
                  - namespace_name = "open-inspect-control-plane-codos_SessionDO" -> null
                  - worker_id      = "3457352971a74b89be5ed3700db48a8e" -> null
                  - worker_name    = "open-inspect-control-plane-codos" -> null
                },
            ] -> (known after apply)
          ~ queues                       = [
              - {
                  - queue_consumer_id = "4e24da4810c84b3e9e80ea014860d145" -> null
                  - queue_id          = "033a23f13783415385b2f8799416c20f" -> null
                  - queue_name        = "open-inspect-github-autofix-codos" -> null
                },
              - {
                  - queue_consumer_id = "f37fe99c4658470aa36767dfb68c3d6f" -> null
                  - queue_id          = "a0647323f7424e778b9d59da50dc55cf" -> null
                  - queue_name        = "open-inspect-image-build-finalization-codos" -> null
                },
            ] -> (known after apply)
          ~ workers                      = [
              - {
                  - id   = "7aa4fa7a556a48708d1ebd7bbba3263a" -> null
                  - name = "open-inspect-web-codos" -> null
                },
              - {
                  - id   = "fa832fd890a14336bc3c63305e9bc36f" -> null
                  - name = "open-inspect-github-bot-codos" -> null
                },
              - {
                  - id   = "049cd48117bc48b9b4332683a97d0a0e" -> null
                  - name = "open-inspect-linear-bot-codos" -> null
                },
              - {
                  - id   = "375c2c6875904657bce05c62c8048c76" -> null
                  - name = "open-inspect-slack-bot-codos" -> null
                },
            ] -> (known after apply)
        } -> (known after apply)
        tags           = []
      ~ updated_on     = "2026-10-05T23:35:59Z" -> (known after apply)
        # (6 unchanged attributes hidden)
    }

  # module.control_plane_worker.cloudflare_worker_version.this must be replaced
-/+ resource "cloudflare_worker_version" "this" {
      ~ annotations         = {
          + workers_message      = (known after apply)
          + workers_tag          = (known after apply)
          ~ workers_triggered_by = "create_version_api" -> (known after apply)
        } -> (known after apply)
      ~ bindings            = (sensitive value) # forces replacement
      ~ created_on          = "2026-10-05T23:36:00Z" -> (known after apply)
      ~ id                  = "9785b074-8fba-423f-b2b4-9a244414f9b4" -> (known after apply)
      + limits              = (known after apply)
      + main_script_base64  = (known after apply)
      ~ migration_tag       = "v1" -> (known after apply)
      ~ number              = 84 -> (known after apply)
      ~ source              = "terraform" -> (known after apply)
      ~ startup_time_ms     = 110 -> (known after apply)
      ~ urls                = [] -> (known after apply)
        # (7 unchanged attributes hidden)
    }

  # module.control_plane_worker.cloudflare_workers_deployment.this must be replaced
-/+ resource "cloudflare_workers_deployment" "this" {
      ~ annotations  = {
          + workers_message      = (known after apply)
          ~ workers_triggered_by = "deployment" -> (known after apply)
        } -> (known after apply)
      + author_email = (known after apply)
      ~ created_on   = "2026-10-05T23:36:02Z" -> (known after apply)
      ~ id           = "b908a483-04e8-45b8-9b2b-603ebe856240" -> (known after apply)
      ~ source       = "terraform" -> (known after apply)
      ~ versions     = [ # forces replacement
          ~ {
              ~ version_id = "9785b074-8fba-423f-b2b4-9a244414f9b4" -> (known after apply)
                # (1 unchanged attribute hidden)
            },
        ]
        # (3 unchanged attributes hidden)
    }

  # module.github_bot_worker[0].cloudflare_worker.this will be updated in-place
  ~ resource "cloudflare_worker" "this" {
        id             = "fa832fd890a14336bc3c63305e9bc36f"
        name           = "open-inspect-github-bot-codos"
      ~ observability  = {
          ~ logs               = {
              + destinations       = (known after apply)
                # (4 unchanged attributes hidden)
            }
          ~ traces             = {
              + destinations       = (known after apply)
                # (3 unchanged attributes hidden)
            }
            # (2 unchanged attributes hidden)
        }
      ~ references     = {
          ~ dispatch_namespace_outbounds = [] -> (known after apply)
          ~ domains                      = [] -> (known after apply)
          ~ durable_objects              = [] -> (known after apply)
          ~ queues                       = [] -> (known after apply)
          ~ workers                      = [
              - {
                  - id   = "3457352971a74b89be5ed3700db48a8e" -> null
                  - name = "open-inspect-control-plane-codos" -> null
                },
            ] -> (known after apply)
        } -> (known after apply)
        tags           = []
      ~ updated_on     = "2026-10-05T23:36:03Z" -> (known after apply)
        # (6 unchanged attributes hidden)
    }

  # module.github_bot_worker[0].cloudflare_worker_version.this must be replaced
-/+ resource "cloudflare_worker_version" "this" {
      ~ annotations         = {
          + workers_message      = (known after apply)
          + workers_tag          = (known after apply)
          ~ workers_triggered_by = "create_version_api" -> (known after apply)
        } -> (known after apply)
      ~ bindings            = (sensitive value) # forces replacement
      ~ created_on          = "2026-10-05T23:36:04Z" -> (known after apply)
      ~ id                  = "eb5355ec-15a8-4fdb-9f6d-bbdda7317b2d" -> (known after apply)
      + limits              = (known after apply)
      + main_script_base64  = (known after apply)
      + migration_tag       = (known after apply)
      ~ number              = 82 -> (known after apply)
      ~ source              = "terraform" -> (known after apply)
      ~ startup_time_ms     = 42 -> (known after apply)
      ~ urls                = [
          - "https://eb5355ec-open-inspect-github-bot-codos.opencodos.workers.dev",
        ] -> (known after apply)
        # (7 unchanged attributes hidden)
    }

  # module.github_bot_worker[0].cloudflare_workers_deployment.this must be replaced
-/+ resource "cloudflare_workers_deployment" "this" {
      ~ annotations  = {
          + workers_message      = (known after apply)
          ~ workers_triggered_by = "deployment" -> (known after apply)
        } -> (known after apply)
      + author_email = (known after apply)
      ~ created_on   = "2026-10-05T23:36:05Z" -> (known after apply)
      ~ id           = "b43a0548-e260-44da-8a70-d19ecf7cefce" -> (known after apply)
      ~ source       = "terraform" -> (known after apply)
      ~ versions     = [ # forces replacement
          ~ {
              ~ version_id = "eb5355ec-15a8-4fdb-9f6d-bbdda7317b2d" -> (known after apply)
                # (1 unchanged attribute hidden)
            },
        ]
        # (3 unchanged attributes hidden)
    }

  # module.linear_bot_worker[0].cloudflare_worker.this will be updated in-place
  ~ resource "cloudflare_worker" "this" {
        id             = "049cd48117bc48b9b4332683a97d0a0e"
        name           = "open-inspect-linear-bot-codos"
      ~ observability  = {
          ~ logs               = {
              + destinations       = (known after apply)
                # (4 unchanged attributes hidden)
            }
          ~ traces             = {
              + destinations       = (known after apply)
                # (3 unchanged attributes hidden)
            }
            # (2 unchanged attributes hidden)
        }
      ~ references     = {
          ~ dispatch_namespace_outbounds = [] -> (known after apply)
          ~ domains                      = [] -> (known after apply)
          ~ durable_objects              = [] -> (known after apply)
          ~ queues                       = [] -> (known after apply)
          ~ workers                      = [
              - {
                  - id   = "3457352971a74b89be5ed3700db48a8e" -> null
                  - name = "open-inspect-control-plane-codos" -> null
                },
            ] -> (known after apply)
        } -> (known after apply)
        tags           = []
      ~ updated_on     = "2026-10-05T23:33:11Z" -> (known after apply)
        # (6 unchanged attributes hidden)
    }

  # module.linear_bot_worker[0].cloudflare_worker_version.this must be replaced
-/+ resource "cloudflare_worker_version" "this" {
      ~ annotations         = {
          + workers_message      = (known after apply)
          + workers_tag          = (known after apply)
          ~ workers_triggered_by = "create_version_api" -> (known after apply)
        } -> (known after apply)
      ~ bindings            = (sensitive value) # forces replacement
      ~ created_on          = "2026-10-05T23:33:12Z" -> (known after apply)
      ~ id                  = "d509693d-eb64-4cce-b532-aad8c0738381" -> (known after apply)
      + limits              = (known after apply)
      + main_script_base64  = (known after apply)
      + migration_tag       = (known after apply)
      ~ number              = 88 -> (known after apply)
      ~ source              = "terraform" -> (known after apply)
      ~ startup_time_ms     = 36 -> (known after apply)
      ~ urls                = [
          - "https://d509693d-open-inspect-linear-bot-codos.opencodos.workers.dev",
        ] -> (known after apply)
        # (7 unchanged attributes hidden)
    }

  # module.linear_bot_worker[0].cloudflare_workers_deployment.this must be replaced
-/+ resource "cloudflare_workers_deployment" "this" {
      ~ annotations  = {
          + workers_message      = (known after apply)
          ~ workers_triggered_by = "deployment" -> (known after apply)
        } -> (known after apply)
      + author_email = (known after apply)
      ~ created_on   = "2026-10-05T23:33:13Z" -> (known after apply)
      ~ id           = "2509595a-aae1-43d1-8716-41a095e0fe03" -> (known after apply)
      ~ source       = "terraform" -> (known after apply)
      ~ versions     = [ # forces replacement
          ~ {
              ~ version_id = "d509693d-eb64-4cce-b532-aad8c0738381" -> (known after apply)
                # (1 unchanged attribute hidden)
            },
        ]
        # (3 unchanged attributes hidden)
    }

  # module.slack_bot_worker[0].cloudflare_worker.this will be updated in-place
  ~ resource "cloudflare_worker" "this" {
        id             = "375c2c6875904657bce05c62c8048c76"
        name           = "open-inspect-slack-bot-codos"
      ~ observability  = {
          ~ logs               = {
              + destinations       = (known after apply)
                # (4 unchanged attributes hidden)
            }
          ~ traces             = {
              + destinations       = (known after apply)
                # (3 unchanged attributes hidden)
            }
            # (2 unchanged attributes hidden)
        }
      ~ references     = {
          ~ dispatch_namespace_outbounds = [] -> (known after apply)
          ~ domains                      = [] -> (known after apply)
          ~ durable_objects              = [] -> (known after apply)
          ~ queues                       = [
              - {
                  - queue_consumer_id = "767c5dfe751c4852a536d98b836cdd94" -> null
                  - queue_id          = "247b1100bac2408684d6a75c1bca0d28" -> null
                  - queue_name        = "open-inspect-slack-completion-codos" -> null
                },
            ] -> (known after apply)
          ~ workers                      = [
              - {
                  - id   = "3457352971a74b89be5ed3700db48a8e" -> null
                  - name = "open-inspect-control-plane-codos" -> null
                },
            ] -> (known after apply)
        } -> (known after apply)
        tags           = []
      ~ updated_on     = "2026-10-05T23:33:11Z" -> (known after apply)
        # (6 unchanged attributes hidden)
    }

  # module.slack_bot_worker[0].cloudflare_worker_version.this must be replaced
-/+ resource "cloudflare_worker_version" "this" {
      ~ annotations         = {
          + workers_message      = (known after apply)
          + workers_tag          = (known after apply)
          ~ workers_triggered_by = "create_version_api" -> (known after apply)
        } -> (known after apply)
      ~ bindings            = (sensitive value) # forces replacement
      ~ created_on          = "2026-10-05T23:33:12Z" -> (known after apply)
      ~ id                  = "02b945c7-5554-4947-b52e-2a26a776293e" -> (known after apply)
      + limits              = (known after apply)
      + main_script_base64  = (known after apply)
      + migration_tag       = (known after apply)
      ~ number              = 86 -> (known after apply)
      ~ source              = "terraform" -> (known after apply)
      ~ startup_time_ms     = 73 -> (known after apply)
      ~ urls                = [
          - "https://02b945c7-open-inspect-slack-bot-codos.opencodos.workers.dev",
        ] -> (known after apply)
        # (7 unchanged attributes hidden)
    }

  # module.slack_bot_worker[0].cloudflare_workers_deployment.this must be replaced
-/+ resource "cloudflare_workers_deployment" "this" {
      ~ annotations  = {
          + workers_message      = (known after apply)
          ~ workers_triggered_by = "deployment" -> (known after apply)
        } -> (known after apply)
      + author_email = (known after apply)
      ~ created_on   = "2026-10-05T23:33:13Z" -> (known after apply)
      ~ id           = "5c21807a-3498-43ad-b1e6-829e1420180d" -> (known after apply)
      ~ source       = "terraform" -> (known after apply)
      ~ versions     = [ # forces replacement
          ~ {
              ~ version_id = "02b945c7-5554-4947-b52e-2a26a776293e" -> (known after apply)
                # (1 unchanged attribute hidden)
            },
        ]
        # (3 unchanged attributes hidden)
    }

Plan: 15 to add, 4 to change, 14 to destroy.

─────────────────────────────────────────────────────────────────────────────

Saved the plan to: tfplan

To perform exactly these actions, run the following command to apply:
    terraform apply "tfplan"

Pushed by: @arodiss

@codos-reviewer codos-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: 0 · Non-blocking: 1

The 7.1.6 override resolves all three former 6.x paths, and the updated lockfile works with npm ci. The shared and web production builds pass. The remaining note concerns the PR description's runtime-dependency classification, not the security fix.

Comment thread packages/web/package.json
},
"devDependencies": {
"@opennextjs/cloudflare": "1.20.7",
"@tailwindcss/typography": "^0.5.19",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] Moving typography to devDependencies is appropriate, but it does not make the parser dev-only: tailwindcss-animate is still a runtime dependency with a Tailwind peer. A clean npm ci --omit=dev still installs Tailwind 3 and postcss-selector-parser@7.1.6. Please qualify the PR description's claim that the alert was mislabeled as runtime, or move the other build-only plugin too if dev-only classification is intended. The security override itself is effective.

@arodiss
arodiss merged commit eda54c5 into main Oct 6, 2026
31 of 32 checks passed
@arodiss
arodiss deleted the fix/postcss-selector-parser-cve branch October 6, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant