2026-10-07
- Security: cleared the flagged copy of
postcss-selector-parserthat lives inside the npm the image ships. npm pins its own dependency tree exactly, so neithernpm install -g npm@latestnor a dependency bump reaches a bundled copy, and the npm in the image still carried 7.1.4. This was the one of the image's three code scanning findings that no dependency bump could fix. The image's npm-bundle repair now lists that package among its targets, so the build replaces the bundled copy with the patched release and fails if any copy of that major line survives.