Skip to content

fix: update minimatch to resolve CVE-2026-27903#183

Merged
dannyneira merged 2 commits into
mainfrom
independabot/minimatch-CVE-2026-27903
Jun 2, 2026
Merged

fix: update minimatch to resolve CVE-2026-27903#183
dannyneira merged 2 commits into
mainfrom
independabot/minimatch-CVE-2026-27903

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

Details

  • Ecosystem: npm
  • Manifest: build_ts/package-lock.json
  • Dependency relationship: transitive development dependency via nodemon
  • Patched version requested by alert: 3.1.3; lockfile now resolves to 3.1.5
  • No resolutions, overrides, or direct dependency additions were needed.

Verification

  • npm ci
  • npm audit --json confirmed minimatch is no longer reported
  • npm run build
  • cargo build
  • cargo clippy --tests -- -A warnings
  • cargo test
  • Baseline note: cargo fmt -- --check reports generated Rust workflow files would be reformatted; those files are unrelated to this lockfile-only fix and were left untouched.

Conversation: https://staging.warp.dev/conversation/75ad0fec-10e0-420f-8ec3-bec51f1b7476
Run: https://oz.staging.warp.dev/runs/019e799d-3281-700d-a2e1-cf1e9bf1b25b
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from vorporeal May 30, 2026 16:08
@dannyneira dannyneira requested a review from vorporeal June 1, 2026 20:04
@dannyneira dannyneira marked this pull request as ready for review June 1, 2026 20:04
@dannyneira dannyneira enabled auto-merge (squash) June 2, 2026 17:24
@dannyneira dannyneira merged commit 5cad3a4 into main Jun 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants