Skip to content

chore: fix dependabot alert in brace-expansion package#481

Merged
hspitzley-czi merged 2 commits intomainfrom
CCIE-5972-high-dependabot-finding-in-isaacs-brace-expansion
Feb 4, 2026
Merged

chore: fix dependabot alert in brace-expansion package#481
hspitzley-czi merged 2 commits intomainfrom
CCIE-5972-high-dependabot-finding-in-isaacs-brace-expansion

Conversation

@hspitzley-czi
Copy link
Contributor

No description provided.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a Dependabot security alert by updating the minimatch package version from ^10.0.1 to ^10.1.2 in the argus-builder build-prep action. The update likely resolves a vulnerability in the transitive dependency brace-expansion that is used by minimatch.

Changes:

  • Updated minimatch package version to patch security vulnerability

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@hspitzley-czi hspitzley-czi merged commit 33833e4 into main Feb 4, 2026
16 of 18 checks passed
@hspitzley-czi hspitzley-czi deleted the CCIE-5972-high-dependabot-finding-in-isaacs-brace-expansion branch February 4, 2026 21:25
@czi-github-helper czi-github-helper bot mentioned this pull request Feb 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants