Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })(); Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 by github-actions[bot] · Pull Request #3103 · vercel/workflow · GitHub
Skip to content

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849 - #3103

Merged
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable
Jul 25, 2026
Merged

Backport #3102: fix: upgrade postcss to >=8.5.18 to address GHSA-r28c-9q8g-f849#3103
TooTallNate merged 1 commit into
stablefrom
backport/pr-3102-to-stable

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Automated backport of #3102 to stable (backport job run).

AI recommendation: This is a pure security dependency bump for a known advisory (GHSA-r28c-9q8g-f849, path traversal in postcss < 8.5.18), with no feature or behavior changes. stable is affected: its lockfile still resolves postcss 8.4.31, 8.5.6, and 8.5.16, all in the vulnerable range, and its pnpm-workspace.yaml has no postcss override at all (the earlier #3067 bump was never backported). The docs/package.json portion won't apply cleanly (docs app isn't maintained on stable and doesn't declare postcss there), but the pnpm-workspace.yaml override plus lockfile update are the substance of the fix and belong on the maintenance line.

Merge conflicts were resolved by AI (opencode with anthropic/claude-opus-5). Please review the conflict resolution carefully before merging.

@changeset-bot

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 0b77d9f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercelBot commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

DiffPackageSupply Chain
Security
VulnerabilityQualityMaintenanceLicense
Updatednpm/​postcss@​8.4.31 ⏵ 8.5.22100+1100+238195100

View full report

@github-actions

github-actionsBot commented Jul 24, 2026

Copy link
Copy Markdown
ContributorAuthor

🧪 E2E Test Results

Some tests failed

Summary

PassedFailedSkippedTotal
✅ ▲ Vercel Production10770781155
✅ 💻 Local Development11740861260
✅ 📦 Local Production11740861260
✅ 🐘 Local Postgres11740861260
✅ 🪟 Windows10500105
❌ 🌍 Community Worlds831019193
✅ 📋 Other594036630
Total53811013815863

❌ Failed Tests

🌍 Community Worlds (101 failed)

redis (18 failed):

  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • pages router sleepingWorkflow via pages router
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

turso (83 failed):

  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • addTenWorkflow | wrun_01KYB4MBSQ70MQQXQX0VKEQ6A2
  • deploymentId: 'latest' is a no-op in non-Vercel worlds
  • wellKnownAgentWorkflow (.well-known/agent) | wrun_01KYB4MFH8YHG82NE8WEZFYR0B
  • should work with react rendering in step
  • promiseAllWorkflow | wrun_01KYB4MMJ31NCJ3NKVQVP9W0M6
  • promiseRaceWorkflow | wrun_01KYB4MSBCWD0X53HQSEW8N3NS
  • promiseAnyWorkflow | wrun_01KYB4MW3AQVX9JSGWP54ZH33M
  • importedStepOnlyWorkflow | wrun_01KYB4MSX6KGTHGW194S2RKAQK
  • readableStreamWorkflow | wrun_01KYB4MYE1BD580759YHVJ68Q3
  • hookWorkflow | wrun_01KYB4NAT43ASTWQ7X6M0YR7BA
  • hookWorkflow is not resumable via public webhook endpoint | wrun_01KYB4NJMKRKP3CMTFNNKAYE48
  • webhookWorkflow | wrun_01KYB4NQ6RED5HQ4AREP9HQYCT
  • parallelStepsThenWebhookWorkflow - no hook_conflict from same-tick replay race | wrun_01KYB4NXB8EXH2XTXDQ24BTSP0
  • sleepingWorkflow | wrun_01KYB4PY2AG1V2TY90XAASMK70
  • parallelSleepWorkflow | wrun_01KYB4QDTBJXXMPMWGPT82JM8D
  • sleepWinsRaceWorkflow | wrun_01KYB4QHQFRVMHQVP7P6CHZ14K
  • stepWinsRaceWorkflow | wrun_01KYB4QN86RB566CZNDY4X4XCC
  • nullByteWorkflow | wrun_01KYB4QRYQCB40HPB3ABCMF96W
  • workflowAndStepMetadataWorkflow | wrun_01KYB4QV92XDRNK2E7P661KX9K
  • outputStreamWorkflow no startIndex (reads all chunks)
  • outputStreamWorkflow positive startIndex (skips first chunk)
  • outputStreamWorkflow negative startIndex (reads from end)
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns correct index after stream completes
  • outputStreamWorkflow - getTailIndex and getStreamChunks getTailIndex returns -1 before any chunks are written
  • outputStreamWorkflow - getTailIndex and getStreamChunks getStreamChunks returns same content as reading the stream
  • outputStreamInsideStepWorkflow - getWritable() called inside step functions | wrun_01KYB4T72YZ8PVQJNPH7TP4Q26
  • writableForwardedFromWorkflowWorkflow | wrun_01KYB4TNKZ9FZ5M69MGTNW20NJ
  • writableForwardedFromStepWorkflow | wrun_01KYB4TSVTD8C1JHF1Y1D004G3
  • fetchWorkflow | wrun_01KYB4TXE2SS3BS2V1FGDV5CR6
  • promiseRaceStressTestWorkflow | wrun_01KYB4V0Y5QSTDV21T9JQ6M1XE
  • error handling error propagation workflow errors nested function calls preserve message and stack trace
  • error handling error propagation workflow errors cross-file imports preserve message and stack trace
  • error handling error propagation step errors basic step error preserves message and stack trace
  • error handling error propagation step errors cross-file step error preserves message and function names in stack
  • error handling retry behavior regular Error retries until success
  • error handling retry behavior FatalError fails immediately without retries
  • error handling retry behavior RetryableError respects custom retryAfter delay
  • error handling retry behavior maxRetries=0 disables retries
  • error handling catchability FatalError can be caught and detected with FatalError.is()
  • error handling not registered WorkflowNotRegisteredError fails the run when workflow does not exist
  • error handling not registered StepNotRegisteredError fails the step but workflow can catch it
  • error handling not registered StepNotRegisteredError fails the run when not caught in workflow
  • hookCleanupTestWorkflow - hook token reuse after workflow completion | wrun_01KYB4YJ3J4KXNEH7J5YX9P0S9
  • concurrent hook token conflict - two workflows cannot use the same hook token simultaneously | wrun_01KYB4YYM6B2Q10PR7MN14TASB
  • hookGetConflictWorkflow - awaiting hook.getConflict() registers hook without payload | wrun_01KYB4ZC1QKV3P336C5R62XK8Z
  • 'hookGetConflictWithPriorStepWorkflow' - hook.getConflict() does not block step execution | wrun_01KYB4ZEKSCK9RRZFRNZ7KSJMY
  • 'hookGetConflictWithParallelStepWorkfl…' - hook.getConflict() does not block step execution | wrun_01KYB4ZJMMKX5A9BZDQAVBAP4K
  • hookGetConflictThenStepParallelWorkflow - hook.getConflict() continuation step runs alongside other steps | wrun_01KYB4ZNBHAEDK293RDYF1379Z
  • hookGetConflictWorkflow - hook.getConflict() resolves with the conflicting run when token is already registered | wrun_01KYB502SN4YGMRY9C4RRGYN3A
  • hookClaimOnlyMutexWorkflow - hook works as a pure run mutex without payload data | wrun_01KYB50Y2YQ7XFZCCKP1G5176E
  • hookAdoptOwnerResultWorkflow - duplicate adopts the owner result via conflict.returnValue | wrun_01KYB51472KEQXNCREZZHQ3SEC
  • hookSignalOwnerWorkflow - duplicate forwards its payload to the owner via resumeHook | wrun_01KYB51A6R0J8GH7CG1ZK14949
  • hookSupersedeOwnerWorkflow - duplicate cancels the owner and claims the released token | wrun_01KYB51F77ZH0Z1FQGDK2M77NS
  • resume-or-start route pattern - resumeHook retried after start() reaches the new run | wrun_01KYB51RFX7GBXZXM9M88V24JR
  • hookDisposeTestWorkflow - hook token reuse after explicit disposal while workflow still running | wrun_01KYB520M4G9A5Y6JVDT05RG1H
  • stepFunctionPassingWorkflow - step function references can be passed as arguments (without closure vars) | wrun_01KYB52PGD5R5N3BFNEA8X73D3
  • stepFunctionWithClosureWorkflow - step function with closure variables passed as argument | wrun_01KYB5309KE0CCV0W2AYD3066Y
  • closureVariableWorkflow - nested step functions with closure variables | wrun_01KYB53690QB21NZTN2C72Z933
  • spawnWorkflowFromStepWorkflow - spawning a child workflow using start() inside a step | wrun_01KYB538P0FNR60W1KM3KT7YRX
  • health check (queue-based) - workflow and step endpoints respond to health check messages
  • health check (CLI) - workflow health command reports healthy endpoints
  • pathsAliasWorkflow - TypeScript path aliases resolve correctly | wrun_01KYB53ST8KT9J4BTTJ87BBC2G
  • Calculator.calculate - static workflow method using static step methods from another class | wrun_01KYB540090EH1MBQFH7PG626P
  • AllInOneService.processNumber - static workflow method using sibling static step methods | wrun_01KYB547AAWYTR4RNSR0TV4QY4
  • ChainableService.processWithThis - static step methods using this to reference the class | wrun_01KYB54DHSQ8RFRRJHWS3RES4Z
  • thisSerializationWorkflow - step function invoked with .call() and .apply() | wrun_01KYB54ND4BQTTSEXW4HAY5238
  • customSerializationWorkflow - custom class serialization with WORKFLOW_SERIALIZE/WORKFLOW_DESERIALIZE | wrun_01KYB54WWNEAFEACBH31K6MK6H
  • instanceMethodStepWorkflow - instance methods with "use step" directive | wrun_01KYB554H8684FQVD4P9JD1K0Y
  • crossContextSerdeWorkflow - classes defined in step code are deserializable in workflow context | wrun_01KYB55JMDVTKTHESAMED70530
  • stepFunctionAsStartArgWorkflow - step function reference passed as start() argument | wrun_01KYB55WZKC85808A4KX837X39
  • cancelRun - cancelling a running workflow | wrun_01KYB56443SZ5TMXGG0PP0TRKE
  • cancelRun via CLI - cancelling a running workflow | wrun_01KYB569XA6RW0YAK5N4XHNGKN
  • pages router addTenWorkflow via pages router
  • pages router promiseAllWorkflow via pages router
  • pages router sleepingWorkflow via pages router
  • hookWithSleepWorkflow - hook payloads delivered correctly with concurrent sleep | wrun_01KYB56JHXBFBY8H2AMATBCG1Z
  • hookWithSleepFinalStepWorkflow - step only on final payload | wrun_01KYB56ZAH8K9S0B3Z5VNF7CEJ
  • sleepInLoopWorkflow - sleep inside loop with steps actually delays each iteration | wrun_01KYB578R7YVPCJKQHKP12DFN0
  • sleepWithSequentialStepsWorkflow - sequential steps work with concurrent sleep (control) | wrun_01KYB57M0XF68468GHWA0HE35M
  • importMetaUrlWorkflow - import.meta.url is available in step bundles | wrun_01KYB57V72B8KCA3EEFHDVFDJ1
  • metadataFromHelperWorkflow - getWorkflowMetadata/getStepMetadata work from module-level helper (#1577) | wrun_01KYB57XJDC1WCC4EES97AF6RV
  • resilient start: addTenWorkflow completes when run_created returns 500 | wrun_01KYB57ZX8BWNJXESQW4FQ549T

Details by Category

✅ ▲ Vercel Production
AppPassedFailedSkipped
✅ astro9708
✅ example9708
✅ express9708
✅ fastify9708
✅ hono9708
✅ nextjs-turbopack10203
✅ nextjs-webpack10203
✅ nitro9708
✅ nuxt9708
✅ sveltekit9708
✅ vite9708
✅ 💻 Local Development
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 📦 Local Production
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🐘 Local Postgres
AppPassedFailedSkipped
✅ astro-stable9906
✅ express-stable9906
✅ fastify-stable9906
✅ hono-stable9906
✅ nextjs-turbopack-canary86019
✅ nextjs-turbopack-stable10500
✅ nextjs-webpack-canary86019
✅ nextjs-webpack-stable10500
✅ nitro-stable9906
✅ nuxt-stable9906
✅ sveltekit-stable9906
✅ vite-stable9906
✅ 🪟 Windows
AppPassedFailedSkipped
✅ nextjs-turbopack10500
❌ 🌍 Community Worlds
AppPassedFailedSkipped
✅ mongodb-dev403
✅ redis-dev403
❌ redis68180
✅ turso-dev403
❌ turso3830
✅ 📋 Other
AppPassedFailedSkipped
✅ e2e-local-dev-nest-stable9906
✅ e2e-local-dev-tanstack-start-stable9906
✅ e2e-local-postgres-nest-stable9906
✅ e2e-local-postgres-tanstack-start-stable9906
✅ e2e-local-prod-nest-stable9906
✅ e2e-local-prod-tanstack-start-stable9906

📋 View full workflow run

@TooTallNate
TooTallNate merged commit 6f234bd into stableJul 25, 2026
95 of 98 checks passed
@TooTallNate
TooTallNate deleted the backport/pr-3102-to-stable branch July 25, 2026 00:32
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@VaguelySerious@TooTallNate