Skip to content

Update fast-glob (micromatch) to resolve security advisory#11173

Merged
aduth merged 1 commit intomainfrom
aduth-micromatch-4-0-8
Aug 30, 2024
Merged

Update fast-glob (micromatch) to resolve security advisory#11173
aduth merged 1 commit intomainfrom
aduth-micromatch-4-0-8

Conversation

@aduth
Copy link
Contributor

@aduth aduth commented Aug 30, 2024

🛠 Summary of changes

Updates micromatch to the latest version to resolve a security advisory.

Advisory: GHSA-952p-6rrq-rcjv

micromatch is a subdependency of fast-glob. While not strictly necessary to update fast-glob as part of this, I did so for good measure (bug fixes and performance improvements).

Approach was to manually remove the top-level entry for micromatch in yarn.lock and re-run yarn install.

📜 Testing Plan

make audit produces no vulnerabilities.

changelog: Internal, Dependencies, Update dependency to resolve security advisory
@aduth aduth merged commit 6c4ba3d into main Aug 30, 2024
@aduth aduth deleted the aduth-micromatch-4-0-8 branch August 30, 2024 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants