Skip to content

fix(deps): remediate vulnerable minimatch via typescript-eslint 8 - #53

Merged
ECorreia45 merged 9 commits into
masterfrom
security/minimatch-typescript-eslint-8
Sep 18, 2026
Merged

ECorreia45 merged 9 commits into
masterfrom
security/minimatch-typescript-eslint-8

Conversation

@ECorreia45

Copy link
Copy Markdown
Contributor

Dependabot cannot update the vulnerable transitive minimatch@9.0.3 because @typescript-eslint 6.x pins that version. This migrates the TypeScript ESLint parser/plugin to v8 while keeping ESLint 8.57.x and the existing eslintrc configuration, avoiding the unrelated ESLint 10 / Node 20 migration in #40.

The PR includes a temporary CI step to regenerate the lockfile and verify lint/tests. That temporary CI scaffolding will be removed before merge once the regenerated lockfile lands.

@ECorreia45
ECorreia45 merged commit 95305e2 into master Sep 18, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant