Skip to content

CWE-1333 vulnerability in minimatch (dependency of glob) #207

@FroYo425

Description

@FroYo425

archiver-utils currently uses glob@10, however that version of glob relies on minimatch@9 which has a CWE-1333 vulnerability.

Could you please update this dependency to glob@11 or higher?

This was reported 2 days ago: GHSA-3ppc-4f35-3m26

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions