Skip to content

chore(deps): bump tailwindcss from 4.2.1 to 4.3.1 in /web - #10

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/tailwindcss-4.3.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/web/tailwindcss-4.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor

Bumps tailwindcss from 4.2.1 to 4.3.1.

Release notes

Sourced from tailwindcss's releases.

v4.3.1

Added

  • Add --silent option to suppress output in @tailwindcss/cli (#20100)

Fixed

  • Remove deprecation warnings by using Module#registerHooks instead of Module#register on Node 26+ (#20028)
  • Canonicalization: don't crash when plugin utilities throw for unsupported values (#20052)
  • Allow @apply to be used with CSS mixins (#19427)
  • Ensure not-* correctly negates @container queries, including style(…) queries (#20059)
  • Ensure drop-shadow-* color utilities work with custom shadow values containing calc(…) (#20080)
  • Fix 'Sourcemap is likely to be incorrect' warnings when using @tailwindcss/vite (#20103)
  • Ensure @tailwindcss/webpack can be installed in Rspack projects without requiring webpack as a peer dependency (#20027)
  • Canonicalization: don't suggest invalid calc(…) expressions (e.g. px-[calc(1rem+0px)]px-[calc(1rem+0)]) (#20127)
  • Canonicalization: avoid suggesting large spacing-scale values for arbitrary lengths (e.g. left-[99999px]left-[99999px], not left-24999.75) (#20130)
  • Ensure @tailwindcss/cli in --watch mode recovers when a tracked dependency is deleted and restored (#20137)
  • Ensure standalone @tailwindcss/cli binaries are ignored when scanning for class candidates (#20139)
  • Ensure class candidates are extracted from Twig addClass(…) and removeClass(…) calls (#20198)
  • Don't crash in the Ruby or Vue preprocessors when scanning files containing invalid UTF-8 bytes (#19588)
  • Allow @variant to be used inside addBase (#19480)
  • Ensure @source globs with symlinks are preserved (#20203)
  • Ensure later @source rules can re-include files excluded by earlier @source not rules (#20203)
  • Upgrade: don't migrate empty class rules to invalid @utility rules (#20205)
  • Ensure transitions between inset-shadow-none and other inset shadows work correctly (#20208)
  • Ensure explicitly referenced @source directories are scanned even when ignored by git (#20214)
  • Ensure @source globs ending in **/* preserve dynamic path segments to avoid scanning too many files (#20217)
  • Canonicalization: don't fold calc(…) divisions when the result would require high precision (e.g. w-[calc(100%/3.5)]w-[calc(100%/3.5)], not w-[28.571428571428573%]) (#20221)
  • Serve ESM type declarations to ESM importers of @tailwindcss/postcss (#20228)

Changed

  • Generate 0 instead of calc(var(--spacing) * 0) for spacing utilities like m-0 and left-0 (#20196)
  • Generate var(--spacing) instead of calc(var(--spacing) * 1) for spacing utilities like m-1 and left-1 (#20196)

v4.3.0

Added

  • Add @container-size utility (#18901)
  • Add scrollbar-{auto,thin,none} utilities for scrollbar-width, and scrollbar-thumb-* / scrollbar-track-* color utilities for scrollbar-color (#19981, #20019)
  • Add scrollbar-gutter-* utilities (#20018)
  • Add zoom-* utilities (#20020)
  • Add tab-* utilities (#20022)
  • Allow using @variant with stacked variants (e.g. @variant hover:focus { … }) (#19996)
  • Allow using @variant with compound variants (e.g. @variant hover, focus { … }) (#19996)
  • Support --default(…) in --value(…) and --modifier(…) for functional @utility definitions (#19989)

Fixed

  • Ensure @plugin resolves package JavaScript entries instead of browser CSS entries when using @tailwindcss/vite (#19949)

... (truncated)

Changelog

Sourced from tailwindcss's changelog.

[4.3.1] - 2026-06-12

Added

  • Add --silent option to suppress output in @tailwindcss/cli (#20100)

Fixed

  • Remove deprecation warnings by using Module#registerHooks instead of Module#register on Node 26+ (#20028)
  • Canonicalization: don't crash when plugin utilities throw for unsupported values (#20052)
  • Allow @apply to be used with CSS mixins (#19427)
  • Ensure not-* correctly negates @container queries, including style(…) queries (#20059)
  • Ensure drop-shadow-* color utilities work with custom shadow values containing calc(…) (#20080)
  • Fix 'Sourcemap is likely to be incorrect' warnings when using @tailwindcss/vite (#20103)
  • Ensure @tailwindcss/webpack can be installed in Rspack projects without requiring webpack as a peer dependency (#20027)
  • Canonicalization: don't suggest invalid calc(…) expressions (e.g. px-[calc(1rem+0px)]px-[calc(1rem+0)]) (#20127)
  • Canonicalization: avoid suggesting large spacing-scale values for arbitrary lengths (e.g. left-[99999px]left-[99999px], not left-24999.75) (#20130)
  • Ensure @tailwindcss/cli in --watch mode recovers when a tracked dependency is deleted and restored (#20137)
  • Ensure standalone @tailwindcss/cli binaries are ignored when scanning for class candidates (#20139)
  • Ensure class candidates are extracted from Twig addClass(…) and removeClass(…) calls (#20198)
  • Don't crash in the Ruby or Vue preprocessors when scanning files containing invalid UTF-8 bytes (#19588)
  • Allow @variant to be used inside addBase (#19480)
  • Ensure @source globs with symlinks are preserved (#20203)
  • Ensure later @source rules can re-include files excluded by earlier @source not rules (#20203)
  • Upgrade: don't migrate empty class rules to invalid @utility rules (#20205)
  • Ensure transitions between inset-shadow-none and other inset shadows work correctly (#20208)
  • Ensure explicitly referenced @source directories are scanned even when ignored by git (#20214)
  • Ensure @source globs ending in **/* preserve dynamic path segments to avoid scanning too many files (#20217)
  • Canonicalization: don't fold calc(…) divisions when the result would require high precision (e.g. w-[calc(100%/3.5)]w-[calc(100%/3.5)], not w-[28.571428571428573%]) (#20221)
  • Serve ESM type declarations to ESM importers of @tailwindcss/postcss (#20228)

Changed

  • Generate 0 instead of calc(var(--spacing) * 0) for spacing utilities like m-0 and left-0 (#20196)
  • Generate var(--spacing) instead of calc(var(--spacing) * 1) for spacing utilities like m-1 and left-1 (#20196)

[4.3.0] - 2026-05-08

Added

  • Add @container-size utility (#18901)
  • Add scrollbar-{auto,thin,none} utilities for scrollbar-width, and scrollbar-thumb-* / scrollbar-track-* color utilities for scrollbar-color (#19981, #20019)
  • Add scrollbar-gutter-* utilities (#20018)
  • Add zoom-* utilities (#20020)
  • Add tab-* utilities (#20022)
  • Allow using @variant with stacked variants (e.g. @variant hover:focus { … }) (#19996)
  • Allow using @variant with compound variants (e.g. @variant hover, focus { … }) (#19996)
  • Support --default(…) in --value(…) and --modifier(…) for functional @utility definitions (#19989)

Fixed

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot @github

dependabot Bot commented on behalf of github May 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, javascript. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from acamarata as a code owner May 17, 2026 19:22
@vercel

vercel Bot commented May 17, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
islamwiki Ready Ready Preview, Comment Jun 13, 2026 2:42pm
ummat-islamwiki Ready Ready Preview, Comment Jun 13, 2026 2:42pm

Request Review

@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 10 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
next HIGH 1117930 Upgrade to version 16.2.5 or later
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later
next HIGH 1118949 Upgrade to version 16.2.5 or later
next HIGH 1118953 Upgrade to version 16.2.5 or later
next HIGH 1118955 Upgrade to version 16.2.5 or later
next HIGH 1118959 Upgrade to version 16.2.5 or later
next HIGH 1118961 Upgrade to version 16.2.5 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 4 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/tailwindcss-4.3.0 branch from 2a3b24a to 589bfcb Compare May 18, 2026 11:11
@github-actions

Copy link
Copy Markdown

🔒 Dependency Audit Failed — 4 HIGH/CRITICAL vulnerability(s)

Package Severity Advisory Fix
@opentelemetry/auto-instrumentations-node HIGH 1117941 Upgrade to version 0.75.0 or later
@opentelemetry/sdk-node HIGH 1117942 Upgrade to version 0.217.0 or later
@opentelemetry/exporter-prometheus HIGH 1117943 Upgrade to version 0.217.0 or later
next HIGH 1118938 Upgrade to version 16.2.6 or later

To resolve: upgrade the affected packages or add an accepted-risk entry to web/.audit-allowlist.json.

Allowlist format
{
  "GHSA-xxxx-xxxx-xxxx": {
    "reason": "No fix available; mitigated by WAF rule #123",
    "expires": "2026-12-31"
  }
}

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/tailwindcss-4.3.0 branch from 589bfcb to 054371b Compare June 9, 2026 22:58
@dependabot dependabot Bot changed the title chore(deps): bump tailwindcss from 4.2.1 to 4.3.0 in /web chore(deps): bump tailwindcss from 4.2.1 to 4.3.1 in /web Jun 13, 2026
Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.2.1 to 4.3.1.
- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)
- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.3.1/packages/tailwindcss)

---
updated-dependencies:
- dependency-name: tailwindcss
  dependency-version: 4.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/web/tailwindcss-4.3.0 branch from 054371b to ec8d91d Compare June 13, 2026 14:39
@acamarata acamarata closed this Jul 1, 2026
@acamarata
acamarata deleted the dependabot/npm_and_yarn/web/tailwindcss-4.3.0 branch July 1, 2026 12:14
@dependabot @github

dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant