Skip to content

build(renovate): update renovate resuable workflow to v1.5.1#16

Merged
marcusrbrown merged 1 commit intomainfrom
build/update-renovate-reusable-workflow-to-v1.5.1
Jul 1, 2023
Merged

build(renovate): update renovate resuable workflow to v1.5.1#16
marcusrbrown merged 1 commit intomainfrom
build/update-renovate-reusable-workflow-to-v1.5.1

Conversation

@marcusrbrown
Copy link
Collaborator

No description provided.

@marcusrbrown marcusrbrown self-assigned this Jul 1, 2023
@marcusrbrown marcusrbrown merged commit 3077360 into main Jul 1, 2023
@marcusrbrown marcusrbrown deleted the build/update-renovate-reusable-workflow-to-v1.5.1 branch July 1, 2023 10:44
Copilot AI added a commit that referenced this pull request Mar 8, 2026
…rabilities

Add pnpm.overrides to force safe minimatch versions:
- minimatch@>=9.0.0 <9.0.7 → ^9.0.9 (was 9.0.5)
- minimatch@>=10.0.0 <10.2.3 → ^10.2.4 (was 10.2.2)

Resolves 5 high-severity Dependabot alerts (#16-#20):
- ReDoS via nested *() extglobs (GHSA)
- ReDoS via multiple non-adjacent GLOBSTAR (GHSA)
- ReDoS via repeated wildcards (GHSA)

Co-authored-by: marcusrbrown <831617+marcusrbrown@users.noreply.github.com>
fro-bot added a commit that referenced this pull request Mar 8, 2026
…y ReDoS CVEs

Adds pnpm override for minimatch to resolve 5 high-severity Dependabot
alerts (#16#20) caused by transitive minimatch@9.0.5 and minimatch@10.2.2
dependencies. All instances now resolve to minimatch@10.2.4.

Addresses: GHSA-minimatch ReDoS via nested extglobs, non-adjacent
GLOBSTAR segments, and repeated wildcards.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant