Skip to content

fix(deps): Update minimatch to >3.1.2 [SECURITY]#5863

Closed
blewis12 wants to merge 3 commits into
mainfrom
update-minimatch-to-above-3.1.2
Closed

fix(deps): Update minimatch to >3.1.2 [SECURITY]#5863
blewis12 wants to merge 3 commits into
mainfrom
update-minimatch-to-above-3.1.2

Conversation

@blewis12
Copy link
Copy Markdown
Member

@blewis12 blewis12 commented Mar 24, 2026

To address this outstanding vulnerabilities:

https://ops.grafana-ops.net/a/grafana-vulnerabilityobs-app/projects/356/version/4964793/cve/43077944
https://ops.grafana-ops.net/a/grafana-vulnerabilityobs-app/projects/356/version/4964793/cve/33073308

As a follow up i'd like to do this without the need for overrides by updating the parent dependencies, but I need to get more aqcuainted with how dependencies work with npm because we might still need to be pinning these at a certain version 🤔

I've built and ran this locally to test it out

@blewis12 blewis12 requested a review from a team as a code owner March 24, 2026 11:46
@blewis12 blewis12 changed the title deps: Update minimatch to >3.1.2 [SECURITY] fix(deps): Update minimatch to >3.1.2 [SECURITY] Mar 24, 2026
@blewis12 blewis12 added the backport/v1.14 Backport to release/v1.14 label Mar 24, 2026
@blewis12
Copy link
Copy Markdown
Member Author

closing in favour of #5872

@blewis12 blewis12 closed this Mar 24, 2026
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Apr 8, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

backport/v1.14 Backport to release/v1.14 frozen-due-to-age

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant