Skip to content

New fast-glob version required due to dependency CVE in micromatch #443

@jimjaeger

Description

@jimjaeger

Hello,

could you please provide a rebuild / new version from fast-glob to bump to new micromatch dependency version 4.0.6

fast-glob 3.3.2 defines a dependency to micromatch.
├─┬ fast-glob@3.3.2
│ │ ├── @nodelib/fs.stat@2.0.5
│ │ ├── @nodelib/fs.walk@1.2.8 deduped
│ │ ├─┬ glob-parent@5.1.2
│ │ │ └── is-glob@4.0.3 deduped
│ │ ├── merge2@1.4.1
│ │ └─┬ micromatch@4.0.5

How to fix?
Upgrade micromatch to version 4.0.6 or higher.
See: https://security.snyk.io/vuln/SNYK-JS-MICROMATCH-6838728

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions