No description
Find a file
Adam Wathan 9ded4a23de
Guard object lookups against inherited prototype properties (#19725)
When user-controlled candidate values like "constructor" are used as
keys to look up values in plain objects (staticValues, plugin values,
modifiers, config), they can match inherited Object.prototype properties
instead of returning undefined. This caused crashes like "V.map is not
a function" when scanning source files containing strings like
"row-constructor".

Use Object.hasOwn() checks before all user-keyed object lookups in:
- utilities.ts (staticValues lookup)
- plugin-api.ts (values, modifiers, and variant values lookups)
- plugin-functions.ts (get() config traversal function)

Fixes #19721

https://claude.ai/code/session_011CYSGw3DLh2Z8xnuyoaCgC

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Robin Malfait <malfait.robin@gmail.com>
2026-02-25 15:16:09 +00:00
.github chore: Update outdated GitHub Actions versions (#19577) 2026-02-18 12:27:13 +00:00
crates 4.2.1 (#19714) 2026-02-23 11:45:12 +01:00
integrations Fallback to config.createResolver for client and ssr environments in @tailwindcss/vite (#19679) 2026-02-17 19:59:57 +00:00
packages Guard object lookups against inherited prototype properties (#19725) 2026-02-25 15:16:09 +00:00
patches Bump dependencies (#19608) 2026-02-04 12:38:50 +01:00
playgrounds Update bun 1.3.7 → 1.3.9 (patch) (#19678) 2026-02-18 12:00:11 +01:00
scripts Make TypeScript a bit more happy (#19124) 2025-10-14 19:52:46 +00:00
.gitignore Fix slow unit test (#17465) 2025-03-31 15:26:01 +02:00
.prettierignore Bump dependencies (#19608) 2026-02-04 12:38:50 +01:00
Cargo.lock Remove unused crossbeam dependency in oxide (#19256) 2025-11-04 10:37:21 -05:00
Cargo.toml Hoist oxide/crates to just crates (#13333) 2024-03-23 09:00:48 -04:00
CHANGELOG.md Guard object lookups against inherited prototype properties (#19725) 2026-02-25 15:16:09 +00:00
LICENSE Add README, LICENSE, and CONTRIBUTING (#13088) 2024-03-05 14:45:39 -05:00
package.json Bump dependencies (#19608) 2026-02-04 12:38:50 +01:00
pnpm-lock.yaml Update bun 1.3.7 → 1.3.9 (patch) (#19678) 2026-02-18 12:00:11 +01:00
pnpm-workspace.yaml Bump dependencies (#19608) 2026-02-04 12:38:50 +01:00
README.md docs: fix GitHub links to tailwindlabs org (#19686) 2026-02-17 13:06:49 +01:00
rust-toolchain.toml Improve Oxide candidate extractor [0] (#16306) 2025-03-05 11:55:24 +01:00
turbo.json Fix segmentation fault when loading @tailwindcss/oxide in a Worker thread (#17276) 2025-03-18 16:28:20 -04:00
vitest.config.ts Bump Vitest to v4 (#19216) 2025-11-20 18:16:20 -05:00

Tailwind CSS

A utility-first CSS framework for rapidly building custom user interfaces.

Build Status Total Downloads Latest Release License


Documentation

For full documentation, visit tailwindcss.com.

Community

For help, discussion about best practices, or feature ideas:

Discuss Tailwind CSS on GitHub

Contributing

If you're interested in contributing to Tailwind CSS, please read our contributing docs before submitting a pull request.