Skip to content

Update NPM packages and fix minimatch ReDoS vulnerability#79

Open
AnHeuermann wants to merge 2 commits intoOpenModelica:mainfrom
AnHeuermann:update-npm
Open

Update NPM packages and fix minimatch ReDoS vulnerability#79
AnHeuermann wants to merge 2 commits intoOpenModelica:mainfrom
AnHeuermann:update-npm

Conversation

@AnHeuermann
Copy link
Copy Markdown
Member

Changes

Bump dependencies to latest compatible versions. Pin prettier-eslint to 16.3.0 (versions 16.3.1–16.4.2 carry a high-severity minimatch ReDoS) and add an overrides entry to force minimatch ≥9.0.7 in its subtree. eslint and typescript are held at v9/v5 respectively due to upstream peer-dependency constraints (eslint-plugin-github, @typescript-eslint).

Bump dependencies to latest compatible versions. Pin prettier-eslint to
16.3.0 (versions 16.3.1–16.4.2 carry a high-severity minimatch ReDoS)
and add an overrides entry to force minimatch ≥9.0.7 in its subtree.
eslint and typescript are held at v9/v5 respectively due to upstream
peer-dependency constraints (eslint-plugin-github, @typescript-eslint).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@AnHeuermann AnHeuermann self-assigned this Mar 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant