Skip to content

Fix minimatch vulnerability, and upgrade npm to v22#1637

Open
marcomura wants to merge 3 commits intomainfrom
mmura/fix-minimatch-vuln
Open

Fix minimatch vulnerability, and upgrade npm to v22#1637
marcomura wants to merge 3 commits intomainfrom
mmura/fix-minimatch-vuln

Conversation

@marcomura
Copy link
Copy Markdown
Collaborator

@marcomura marcomura commented Feb 20, 2026

minimatch <10.2.1
Severity: high
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - GHSA-3ppc-4f35-3m26


Rovo Dev code review: Rovo Dev has reviewed this pull request
Any suggestions or improvements have been posted as pull request comments.

@marcomura marcomura enabled auto-merge (squash) February 20, 2026 00:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants