Skip to content

Bump the twentynineteen-css-sass group across 1 directory with 3 updates - #577

Open
dependabot[bot] wants to merge 35 commits into
trunkfrom
dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0
Open

Bump the twentynineteen-css-sass group across 1 directory with 3 updates#577
dependabot[bot] wants to merge 35 commits into
trunkfrom
dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubMay 18, 2026

Copy link
Copy Markdown

Bumps the twentynineteen-css-sass group with 3 updates in the /src/wp-content/themes/twentynineteen directory: @wordpress/browserslist-config, autoprefixer and postcss.

Updates @wordpress/browserslist-config from 6.34.0 to 6.52.0

Changelog

Sourced from @​wordpress/browserslist-config's changelog.

6.52.0 (2026-07-29)

6.51.0 (2026-07-14)

6.50.0 (2026-07-01)

6.49.0 (2026-06-24)

6.48.1 (2026-06-16)

6.48.0 (2026-06-10)

6.47.0 (2026-05-27)

6.46.0 (2026-05-14)

6.45.0 (2026-04-29)

6.44.0 (2026-04-15)

6.43.0 (2026-04-01)

6.42.0 (2026-03-18)

6.41.0 (2026-03-04)

6.40.0 (2026-02-18)

6.39.0 (2026-01-29)

6.38.0 (2026-01-16)

6.36.0 (2025-11-26)

6.35.0 (2025-11-12)

Commits
  • 7e8b17a chore(release): publish
  • 42ad080 Update changelog files
  • e9a74f9 chore(release): publish
  • 2a0c375 Update changelog files
  • e61c854 Merge changes published in the Gutenberg plugin "release/23.6" branch
  • 1055a35 Update changelog files
  • 8ca3e8e Merge changes published in the Gutenberg plugin "release/23.6" branch
  • 66c8050 Fix wp/latest release metadata (#79821)
  • d0d1bfc Update changelog files
  • 66315f3 Merge changes published in the Gutenberg plugin "release/23.5" branch
  • Additional commits viewable in compare view

Updates autoprefixer from 10.4.22 to 10.5.4

Release notes

Sourced from autoprefixer's releases.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

10.5.0 “Each Endeavouring, All Achieving”

  • Added mask-position-x and mask-position-y support (by @​toporek).

10.4.27

  • Removed development key from package.json.

10.4.26

  • Reduced package size.

10.4.25

  • Fixed broken gradients on CSS Custom Properties (by @​serger777).

10.4.24

  • Made Autoprefixer a little faster (by @​Cherry).

10.4.23

Changelog

Sourced from autoprefixer's changelog.

10.5.4

10.5.3

10.5.2

  • Moved -webkit-fill-available before -moz-available, so Firefox will use -webkit- version which is closer to stretch.

10.5.1

10.5.0 “Each Endeavouring, All Achieving”

  • Added mask-position-x and mask-position-y support (by @​toporek).

10.4.27

  • Removed development key from package.json.

10.4.26

  • Reduced package size.

10.4.25

  • Fixed broken gradients on CSS Custom Properties (by @​serger777).

10.4.24

  • Made Autoprefixer a little faster (by @​Cherry).

10.4.23

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for autoprefixer since your current version.


Updates postcss from 8.5.6 to 8.5.25

Release notes

Sourced from postcss's releases.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

8.5.15

  • Fixed declaration parsing performance (by @​homanp).

8.5.14

8.5.13

  • Fixed postcss-scss commend regression.

8.5.12

  • Fixed reading any file via user-generated CSS.

... (truncated)

Changelog

Sourced from postcss's changelog.

8.5.25

  • Fixed 8.5.17 visitor regression.
  • Fixed list.split() for non-string values (by @​amir-rezaei).

8.5.24

  • Preserve the BOM after the processing (by @​hdimer).

8.5.23

  • Do not load source map without opts.from for security reasons.

8.5.22

8.5.21

8.5.20

8.5.19

8.5.18

  • Restricted loading previous source maps file to the opts.from folder for security reasons (use unsafeMap: true to disable the check).

8.5.17

  • Fixed Maximum call stack size exceeded error.
  • Fixed Prototype hijacking for postcss.fromJSON().
  • Fixed Input#origin() for unmapped end position (by @​chatman-media).

8.5.16

8.5.15

... (truncated)

Commits
Maintainer changes

This version was pushed to npm by GitHub Actions, a new releaser for postcss since your current version.


@dependabotdependabotBot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels May 18, 2026
@desrosj
desrosjforce-pushed the trunk branch 2 times, most recently from e29f070 to 7eb09cfCompareMay 21, 2026 03:52
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch 2 times, most recently from 18b6e18 to 8dc7219CompareMay 21, 2026 04:24
@desrosj
desrosjforce-pushed the trunk branch 4 times, most recently from 3edb3b0 to f6510e8CompareMay 22, 2026 13:34
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from 8dc7219 to 8a335aaCompareMay 25, 2026 05:34
@desrosj
desrosjforce-pushed the trunk branch 3 times, most recently from c6cb69a to 7f3380bCompareJune 12, 2026 04:21
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from 8a335aa to f7550c5CompareJune 15, 2026 04:39
@desrosj
desrosjforce-pushed the trunk branch 2 times, most recently from ac3bbc2 to 6044c40CompareJune 19, 2026 19:36
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from f7550c5 to e4e542fCompareJune 22, 2026 04:34
@desrosj
desrosjforce-pushed the trunk branch 2 times, most recently from 967c01d to 24f2eaeCompareJune 25, 2026 23:30
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from e4e542f to 1d06319CompareJune 29, 2026 04:26
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from 1d06319 to 4aeee17CompareJuly 6, 2026 04:26
@desrosj
desrosjforce-pushed the trunk branch 2 times, most recently from bda8dd7 to 1c7c6f5CompareJuly 10, 2026 18:09
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from 4aeee17 to 44121dbCompareJuly 13, 2026 04:27
@desrosj
desrosjforce-pushed the trunk branch 2 times, most recently from 0868522 to 7de0505CompareJuly 14, 2026 19:52
desrosjand others added 26 commits August 5, 2026 09:17
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…kflow.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…decouple trunk job.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…spatch for Gutenberg Sync.
- Remove the dry_run input and all DRY_RUN handling.
- Replace the auto-detecting setup job with a workflow-level
CURRENTLY_SUPPORTED_BRANCH env var (mirrors test-old-branches.yml).
- Replace the target choice input with a free-form branch input accepting
"trunk" or an X.Y branch name; scheduled runs update trunk plus the
currently supported branch, while a manual run targets one branch.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ch job.
- Remove the schedule trigger; the workflow now runs only on workflow_dispatch.
- Make the branch input required with a default of "trunk".
- Merge the trunk and version-branch jobs into one "sync" job; trunk- and
version-specific work is gated on inputs.branch, and the token, checkout,
body-building, PR lookup, and PR create/update steps are shared.
- Split steps to be atomic: resolve SHA, build PR body, look up the existing
PR, and create/update the PR are now separate steps.
- Drop the now-unused CURRENTLY_SUPPORTED_BRANCH env var.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… env vars.
Define BASE_BRANCH and HEAD_BRANCH as workflow-level environment variables
derived from the branch input, and remove the explicit determine/validate
step. An invalid branch now fails at the checkout step, which is sufficient.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…upstream.
WordPress/wordpress-develop does not accept pushed branches, so the workflow
now runs from a fork:
- Guard inverted to run only on forks (github.repository != upstream).
- Check out the target branch from upstream so the PR is built on current
content, push the gutenberg-sync/<branch> branch to the fork, and open the
pull request from the fork branch back to upstream.
- Drop the canonical-only GitHub App token (its private key cannot live on a
fork). Push with the built-in GITHUB_TOKEN; open/label the upstream PR with
an optional GUTENBERG_SYNC_TOKEN PAT. Without the PAT, the branch is still
pushed and the run prints a link to open the PR manually.
- Skip creating a duplicate when an open Gutenberg Sync PR already exists for
the target branch from another fork.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…he wp/X.Y existence check.
- Replace the manual git clone of WordPress/gutenberg with an actions/checkout
step (fetch-depth: 0 so the changelog's git log range has history), and read
the new SHA from the checked-out head.
- Remove the custom "wp/<branch> does not exist" guard; if the branch is
missing, the Gutenberg checkout fails on its own, which is sufficient.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…mplate.
Move the PR body structure into .github/workflows/gutenberg-sync-pr-body.md
with __BRANCH__, __NEW_SHA__, __SOURCE_LINE__, and __CHANGELOG__ placeholders.
The resolve steps now only emit the scalar values and write the changelog
content to a file; a single awk step renders the template (inserting the
changelog file verbatim so untrusted release notes are never re-substituted).
The template is sparse-checked-out from the workflow's own ref so it is always
available and version-matched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…beling.
- Render the PR body by writing each placeholder into a working copy of the
template as its value is resolved (sed for scalars, awk to insert the
changelog verbatim). This removes the SOURCE_LINE environment variable and
the separate body-building step.
- Stop applying the label in the sync workflow and identify an existing PR by
the gutenberg-sync/<branch> head branch name instead of the label.
- Add gutenberg-sync-label.yml: on pull_request_target (opened/reopened) it
labels any gutenberg-sync/* PR using upstream's token, which (unlike the
fork's token) can label PRs on upstream. It never checks out PR code, so the
pull_request_target trigger is safe (zizmor ignore documented inline).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… the template.
- Move the body template to .github/template-gutenberg-sync-pr-body.md.
- Break each resolve path into one action per step (copy template, fill each
placeholder, retrieve release details / determine SHAs, build changelog).
- Break the push into create-branch, update-file, stage, commit, add-remote,
and push steps.
- Split the pull request step into lookup, update-existing, and open-new.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…n-branch jobs.
Gate the branch selection at the job level (inputs.branch == 'trunk' vs
!= 'trunk') so the per-step branch conditionals are no longer needed. Each job
runs end to end: checkout, resolve, push to the fork, and open/update the PR.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…sable workflow.
Add reusable-gutenberg-sync-pr.yml (workflow_call) that pushes the
gutenberg-sync/<branch> branch to the fork and opens or updates the upstream
pull request. The trunk and version-branch jobs now only resolve the new SHA,
title, and body (uploaded as an artifact) and expose them as outputs; the
open-pull-request job calls the reusable workflow with those values. This
removes the push/PR steps that were duplicated across the two jobs.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ranch conditions.
Remove the reusable-gutenberg-sync-pr.yml workflow and the resolve/publish job
split, returning to one sync job whose trunk- and version-specific steps are
gated with inputs.branch conditions.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…y instead of opening a PR.
The compare link cannot carry the generated body, so stop creating/updating the
pull request (and drop the GUTENBERG_SYNC_TOKEN PAT). The workflow now pushes the
branch to the fork and writes the PR title and body to the job summary, with the
body in a fenced block for copy/paste into a manually opened pull request.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The reorganized workflow split resolve, body-building, and push into separate
jobs, but the data did not cross the job boundaries. Fix that:
- Expose research's resolved values (new/old SHA, title, tag, release URL,
proceed) as job outputs and consume them downstream via needs.research.outputs.
- Gate build-pr-body and create-update-branch at the job level on the proceed
output instead of the per-step env.PROCEED checks, which were empty in those
jobs.
- Pass the changelog between jobs as an artifact.
- Reorder research so the changelog is built after the SHAs are determined.
- Build the PR body template from the fork (sparse checkout) and fix the
pr_body.md filename and the missing changelog insertion for version branches.
- Correct the create-update-branch permission (contents: write) and scope the
read-only jobs to contents: read.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…a details block, and fix the SHA placeholder.
- Add a list of changes (git log --reverse OLD..NEW, linkified) to every PR
body, right after the intro line. Trunk now also checks out Gutenberg (at the
release tag) so the list can be built, and the new SHA is read uniformly via
git rev-parse.
- For trunk, extract only the release's "## Changelog" section (which drops the
heading and the First-time contributors/Contributors sections) and place it in
a collapsed <details> labeled "Changelog"; remove the "## Changes" heading.
- Pass the commit list and release changelog between jobs as artifacts.
- Fix the __NEW_SHA__ replacement by giving the step its NEW_SHA env value.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… sections.
- Add a step to substitute the new __OLD_SHA__ placeholder.
- Rename the first details summary to "Changes" (it holds the commit list and
source link); the second remains "Changelog" for the release notes.
- For version branches, remove the entire changelog <details> block rather than
just the placeholder line, so the body has no empty collapsible.
- Insert the release changelog directly now that the template supplies the
<details> wrapper.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…ping.
- Update the pull request titles and job-summary headings.
- Escape the backticks in the PR titles so the shell treats them as literal
text instead of command substitution (which blanked the code references).
- Restore the blank lines around __CHANGELOG__ in the template so the release
changelog renders as Markdown inside the <details> block.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…e branch input.
- Run the single Gutenberg checkout for both trunk and version branches, after
the release details are retrieved (so the trunk ref resolves to the release
tag), and target wp/X.Y for version branches.
- Make the branch input a choice so only allowed values can be dispatched.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Bumps the twentynineteen-css-sass group with 3 updates in the /src/wp-content/themes/twentynineteen directory: [@wordpress/browserslist-config](https://github.com/WordPress/gutenberg/tree/HEAD/packages/browserslist-config), [autoprefixer](https://github.com/postcss/autoprefixer) and [postcss](https://github.com/postcss/postcss).
Updates `@wordpress/browserslist-config` from 6.34.0 to 6.52.0
- [Release notes](https://github.com/WordPress/gutenberg/releases)
- [Changelog](https://github.com/WordPress/gutenberg/blob/trunk/packages/browserslist-config/CHANGELOG.md)
- [Commits](https://github.com/WordPress/gutenberg/commits/@wordpress/browserslist-config@6.52.0/packages/browserslist-config)
Updates `autoprefixer` from 10.4.22 to 10.5.4
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.4.22...10.5.4)
Updates `postcss` from 8.5.6 to 8.5.25
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.6...8.5.25)
---
updated-dependencies:
- dependency-name: "@wordpress/browserslist-config"
dependency-version: 6.46.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: twentynineteen-css-sass
- dependency-name: autoprefixer
dependency-version: 10.5.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: twentynineteen-css-sass
- dependency-name: postcss
dependency-version: 8.5.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: twentynineteen-css-sass
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabotBotforce-pushed the dependabot/npm_and_yarn/src/wp-content/themes/twentynineteen/twentynineteen-css-sass-0790bd58e0 branch from 959c544 to e757f20CompareAugust 10, 2026 04:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filejavascriptPull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@desrosj