Skip to content

Update npm dependencies to address security vulnerabilities - #80

Merged
Eliran Eretz-Kedosha (eliranek1) merged 3 commits into
masterfrom
user/bviswanathan/security-fix
Mar 6, 2026
Merged

Update npm dependencies to address security vulnerabilities#80
Eliran Eretz-Kedosha (eliranek1) merged 3 commits into
masterfrom
user/bviswanathan/security-fix

Conversation

@balaji-viswanathan

@balaji-viswanathan balaji-viswanathan commented Mar 4, 2026

Copy link
Copy Markdown
Contributor

Upgrades minimatch to 3.1.3 to address security vulnerability.

https://domoreexp.visualstudio.com/MSTeams/_workitems/edit/5202990/?view=edit

Comment thread yarn.lock
@balaji-viswanathan
balaji-viswanathan force-pushed the user/bviswanathan/security-fix branch from b80bd35 to 5af8716 Compare March 5, 2026 00:10

@thomastay Thomas Tay (thomastay) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is good but note that resolutions don't apply across packages (i.e. this will only resolve for ObjectStoreProvider in Github, but not in TMP)

@balaji-viswanathan

Copy link
Copy Markdown
Contributor Author

this is good but note that resolutions don't apply across packages (i.e. this will only resolve for ObjectStoreProvider in Github, but not in TMP)

right, but the reported security issue points to objectstoreprovider usage of this library and if there are instances of this used in TMP outside of this, it would have been flagged separately, but we don't see that.

@eliranek1
Eliran Eretz-Kedosha (eliranek1) merged commit fa096ef into master Mar 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants