Skip to content

[rushstack] minimatch needs to be upgraded #5648

@cmalonzo

Description

@cmalonzo

Summary

Current version of minimatch in the rush repo has a known high vulnerability:
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
GHSA-3ppc-4f35-3m26

Solve this in part by bumping version to 10.2.1.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status

    Needs triage

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions