Skip to content

Security: fix Dependabot alert #9 for minimatch (GHSA-7r86-cg39-jmmj) #26

@slashdevcorpse

Description

@slashdevcorpse

Dependabot Alert

Summary

minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments

Remediation

  • Update the dependency graph so minimatch resolves outside the vulnerable range.
  • Regenerate pnpm-lock.yaml.
  • Run the app test/build checks and package dry run.
  • Confirm GitHub Dependabot marks alert chore(deps-dev): bump vite from 7.3.1 to 7.3.2 #9 resolved after merge.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependabot-alertGitHub Dependabot security alert trackingdependenciesPull requests that update a dependency filesecuritySecurity advisories and vulnerability remediation

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions