Skip to content

build(deps): bump minimatch from 9.0.5 to 9.0.7 in /_integration-test/nodejs#4189

Merged
aldy505 merged 1 commit intomasterfrom
dependabot/npm_and_yarn/_integration-test/nodejs/minimatch-9.0.7
Feb 26, 2026
Merged

build(deps): bump minimatch from 9.0.5 to 9.0.7 in /_integration-test/nodejs#4189
aldy505 merged 1 commit intomasterfrom
dependabot/npm_and_yarn/_integration-test/nodejs/minimatch-9.0.7

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 25, 2026

Bumps minimatch from 9.0.5 to 9.0.7.

Commits
  • 2de496f 9.0.7
  • 0d4616d limit nested extglob recursion, flatten extglobs
  • 7117ef3 9.0.6
  • 2418458 update deps, do not checkin dist
  • 1d1f531 update deps
  • 03b1778 update CI matrix and actions
  • f1aaffe update test expectations for coalesced consecutive stars
  • 5012655 coalesce consecutive non-globstar * characters
  • 3515d1e [meta] add publishConfig.tag legacy-v9
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [minimatch](https://github.com/isaacs/minimatch) from 9.0.5 to 9.0.7.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](isaacs/minimatch@v9.0.5...v9.0.7)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 9.0.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Feb 25, 2026
@github-actions
Copy link

github-actions bot commented Feb 25, 2026

Changelog Preview

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


Bug Fixes 🐛

  • Prevent script injection vulnerability in get-compose-action by fix-it-felix-sentry in #4179

Internal Changes 🔧

Deps

  • Bump minimatch from 9.0.5 to 9.0.7 in /_integration-test/nodejs by dependabot[bot] in #4189
  • Bump getsentry/craft from 2.21.4 to 2.21.7 by dependabot in #4188

Other

  • Use docker-compose shipped in GHA runners by aminvakil in #4184

🤖 This preview updates automatically when you update the PR.

1 similar comment
@github-actions
Copy link

Changelog Preview

📋 Changelog Preview

This is how your changes will appear in the changelog.
Entries from this PR are highlighted with a left border (blockquote style).


Bug Fixes 🐛

  • Prevent script injection vulnerability in get-compose-action by fix-it-felix-sentry in #4179

Internal Changes 🔧

Deps

  • Bump minimatch from 9.0.5 to 9.0.7 in /_integration-test/nodejs by dependabot[bot] in #4189
  • Bump getsentry/craft from 2.21.4 to 2.21.7 by dependabot in #4188

Other

  • Use docker-compose shipped in GHA runners by aminvakil in #4184

🤖 This preview updates automatically when you update the PR.

@aminvakil
Copy link
Collaborator

Failing test is unrelated to change:

failed to solve: altinity/clickhouse-server:25.3.6.10034.altinitystable: failed to resolve source metadata for docker.io/altinity/clickhouse-server:25.3.6.10034.altinitystable: failed to copy: httpReadSeeker: failed open: unexpected status code https://registry-1.docker.io/v2/altinity/clickhouse-server/blobs/sha256:69114f371d302c65b7b540f23e001778c9face49c5f299646054d03c5e2a2c78: 504 Gateway Time-out

Closing and reopening to rerun CI.

@aminvakil aminvakil closed this Feb 25, 2026
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 25, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@aminvakil aminvakil reopened this Feb 25, 2026
@aldy505 aldy505 merged commit 0d73a94 into master Feb 26, 2026
29 of 32 checks passed
@aldy505 aldy505 deleted the dependabot/npm_and_yarn/_integration-test/nodejs/minimatch-9.0.7 branch February 26, 2026 03:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants