Skip to content

Security: fix Dependabot alert #10 for minimatch (GHSA-7r86-cg39-jmmj) #27

@slashdevcorpse

Description

@slashdevcorpse

Dependabot Alert

Summary

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Remediation

  • Update the dependency graph so minimatch resolves outside the vulnerable range.
  • Regenerate pnpm-lock.yaml.
  • Run the app test/build checks and package dry run.
  • Confirm GitHub Dependabot marks alert Add GitHub contribution templates #10 resolved after merge.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependabot-alertGitHub Dependabot security alert trackingdependenciesPull requests that update a dependency filesecuritySecurity advisories and vulnerability remediation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions