Skip to content

[-]:fix/Dependanbot alerts by adding minimatch#1801

Merged
jaaaaavier merged 13 commits intomainfrom
fix/dependencies-alert
Feb 24, 2026
Merged

[-]:fix/Dependanbot alerts by adding minimatch#1801
jaaaaavier merged 13 commits intomainfrom
fix/dependencies-alert

Conversation

@jaaaaavier
Copy link
Contributor

Resolved several High severity security vulnerabilities reported in the project dependencies originating from the minimatch package (ReDoS vulnerability).

Added "/minimatch": "^10.2.2" to the resolutions block in package.json to force yarn to install a patch-level version free from the vulnerability throughout the entire dependency tree.

@jaaaaavier jaaaaavier self-assigned this Feb 24, 2026
@jaaaaavier jaaaaavier added the dependencies Pull requests that update a dependency file label Feb 24, 2026
@vercel
Copy link

vercel bot commented Feb 24, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
website Ready Ready Preview, Comment Feb 24, 2026 10:46am

@sonarqubecloud
Copy link

Quality Gate Failed Quality Gate failed

Failed conditions
0.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@jaaaaavier jaaaaavier merged commit e1d02b2 into main Feb 24, 2026
8 of 10 checks passed
@jaaaaavier jaaaaavier deleted the fix/dependencies-alert branch February 24, 2026 10:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants