Skip to content

fix: update picomatch to resolve CVE-2026-33672#236

Draft
dannyneira wants to merge 1 commit into
mainfrom
independabot/picomatch-cve-2026-33672
Draft

fix: update picomatch to resolve CVE-2026-33672#236
dannyneira wants to merge 1 commit into
mainfrom
independabot/picomatch-cve-2026-33672

Conversation

@dannyneira
Copy link
Copy Markdown
Member

Summary

  • Updates transitive picomatch entries in package-lock.json from 2.3.1 to 2.3.2 and from 4.0.2 to 4.0.4.
  • Regenerates the bundled GitHub Action output in dist/.
  • Resolves CVE-2026-33672 / GHSA-3v7f-55p6-f55p for both affected lockfile entries.

Vulnerability details

Verification

  • npx --yes npm@8 ci
  • npx --yes npm@8 audit --json confirmed no remaining picomatch vulnerability entries. Other unrelated existing alerts remain.
  • npm run build
  • npm run format-check
  • npm run lint
  • npm run package

Conversation: https://staging.warp.dev/conversation/0f640c51-fb81-47a6-b827-f9c5a2e1957b
Run: https://oz.staging.warp.dev/runs/019e36aa-7520-7c8d-ac1e-5ac0014872e1
This PR was generated with Oz.

Co-Authored-By: Oz <oz-agent@warp.dev>
@dannyneira dannyneira requested a review from zachbai May 17, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant