Skip to content

Commit 754d1dc

Browse files
ParakhJaggiAndyBitz
authored andcommitted
fix: update minimatch to 3.1.5 to resolve security vulnerabilities (#228)
* fix: update minimatch to 3.1.5 to resolve security vulnerabilities Bumps minimatch from 3.1.2 to 3.1.5, the latest patch in the 3.x line. This resolves the following CVEs: - GHSA-3ppc-4f35-3m26 (ReDoS via repeated wildcards, high severity) - GHSA-7r86-cg39-jmmj (ReDoS via multiple non-adjacent GLOBSTAR segments, high severity) - GHSA-23c5-xmqv-rm74 (ReDoS via nested *() extglobs, high severity) Fixes #206 * chore: update yarn.lock for minimatch 3.1.5
1 parent 8b357fa commit 754d1dc

2 files changed

Lines changed: 9 additions & 2 deletions

File tree

package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@
5959
"bytes": "3.0.0",
6060
"content-disposition": "0.5.2",
6161
"mime-types": "2.1.18",
62-
"minimatch": "3.1.2",
62+
"minimatch": "3.1.5",
6363
"path-is-inside": "1.0.2",
6464
"path-to-regexp": "3.3.0",
6565
"range-parser": "1.2.0"

yarn.lock

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2388,7 +2388,14 @@ mimic-fn@^2.1.0:
23882388
resolved "https://registry.yarnpkg.com/mimic-fn/-/mimic-fn-2.1.0.tgz#7ed2c2ccccaf84d3ffcb7a69b57711fc2083401b"
23892389
integrity sha512-OqbOk5oEQeAZ8WXWydlu9HJjz9WVdEIvamMCcXmuqUYjTknH/sqsWvhQ3vgwKFRR1HpjvNBKQ37nbJgYzGqGcg==
23902390

2391-
minimatch@3.1.2, minimatch@^3.0.4, minimatch@^3.1.1:
2391+
minimatch@3.1.5:
2392+
version "3.1.5"
2393+
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.5.tgz#580c88f8d5445f2bd6aa8f3cadefa0de79fbd69e"
2394+
integrity sha512-VgjWUsnnT6n+NUk6eZq77zeFdpW2LWDzP6zFGrCbHXiYNul5Dzqk2HHQ5uFH2DNW5Xbp8+jVzaeNt94ssEEl4w==
2395+
dependencies:
2396+
brace-expansion "^1.1.7"
2397+
2398+
minimatch@^3.0.4, minimatch@^3.1.1:
23922399
version "3.1.2"
23932400
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.2.tgz#19cd194bfd3e428f049a70817c038d89ab4be35b"
23942401
integrity sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==

0 commit comments

Comments
 (0)