Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Minimatch version update #464

Closed
mmedvedik opened this issue Mar 21, 2022 · 2 comments
Closed

Minimatch version update #464

mmedvedik opened this issue Mar 21, 2022 · 2 comments

Comments

@mmedvedik
Copy link

I found minimatch v3.0.4 currently resolved version by the latest glob contains an RDOS vulnerability: https://www.huntr.dev/bounties/e4e1393c-d590-4492-9f43-8be3f3321629/ . Since critical changes in v3.0.5 (isaacs/minimatch#153) the minimatch version will not update itself (glob package.json accepts only patch versions updates). Do you plan to upgrade minimatch dependencies to v3.0.5 or higher?

@animatedboy
Copy link

animatedboy commented Apr 6, 2022

I see the new release tag 7.2.1 which has the changes for minimatch. And its not pushed to npm registry. When can we expect this version to be pushed to registry?

@akerpelm
Copy link

akerpelm commented Apr 7, 2022

also curious if there is any estimated completion to resolve this.

@isaacs isaacs closed this as completed in 6ad3bbf Apr 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants