Skip to content

Conversation

@bb111189
Copy link
Contributor

Summary

Upgrades glob from v10.4.5 to v11.1.0 to fix a high severity security vulnerability.

Details

  • Resolves: Dependabot Alert feat: upgrade fp depends and delete fork codes #82
  • Advisory: GHSA-8g2g-xc48-r68v
  • Severity: High
  • Vulnerability: Command injection via -c/--cmd executes matches with shell:true
  • Vulnerable versions: >= 10.3.7, <= 11.0.3
  • Patched version: v11.1.0

Changes

  • Added resolutions field in package.json to force glob version to ^11.1.0
  • Updated yarn.lock to use glob v11.1.0 with verified checksums

Fixes #82

Resolves dependabot alert #82 (GHSA-8g2g-xc48-r68v)
Fixes high severity vulnerability: command injection via -c/--cmd executes matches with shell:true
@github-actions github-actions bot added bug Something isn't working S labels Nov 17, 2025
@bb111189 bb111189 requested a review from fyInALT November 17, 2025 18:14
@fyInALT fyInALT merged commit e24baa2 into master Nov 17, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working S

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants