Commit 6d9d7ce
UID2-6675: upgrade minimatch to fix CVE-2026-27903 ReDoS
Adds minimatch override to pin to patched version:
- overrides/minimatch: (new) ^10.2.3
CVE-2026-27903 / GHSA-7r86-cg39-jmmj: ReDoS via multiple GLOBSTAR
segments in matchOne(), affects minimatch <3.1.3 and <10.2.3.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 341f155 commit 6d9d7ce
2 files changed
Lines changed: 48 additions & 13 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
54 | | - | |
| 54 | + | |
55 | 55 | | |
56 | 56 | | |
57 | 57 | | |
| |||
0 commit comments