DataDog / datadog-ci

Use Datadog from your CI.
https://datadoghq.com
Apache License 2.0
127 stars 55 forks source link

Yarn audit High : minimatch from glob dependencies #701

Closed ellisium closed 1 year ago

ellisium commented 1 year ago

Please update your glob dependency to fix minimatch version

┌───────────────┬──────────────────────────────────────────────────────────────┐ │ high │ minimatch ReDoS vulnerability │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ minimatch │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=3.0.5 │ ├───────────────┼─────────────────────────────────────────── ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ @datadog/datadog-ci > glob > minimatch │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://www.npmjs.com/advisories/1084765

lefebvree commented 1 year ago

Hello @ellisium, this has been addressed in https://github.com/DataDog/datadog-ci/pull/702 and released with v2.1.0.