Skip to content

fix(deps): override minimatch >=10.2.1 to fix ReDoS (Dependabot #2) - #33

Merged
intech merged 1 commit into
mainfrom
fix/minimatch-redos
Feb 20, 2026
Merged

intech merged 1 commit into
mainfrom
fix/minimatch-redos

Conversation

@intech

@intech intech commented Feb 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Added a pnpm.overrides entry for minimatch@<10.2.1 → 10.2.1 in the root package.json
  • Fixes Dependabot alert #2: ReDoS via repeated wildcards in minimatch <10.2.1 (severity: HIGH)
  • minimatch is a transitive devDependency (c8 → test-exclude → minimatch) and does not reach the published packages

Changes

File Change
package.json Added "minimatch@<10.2.1": "10.2.1" to pnpm.overrides
pnpm-lock.yaml Auto-updated by pnpm install

Verification

$ pnpm why minimatch
# All instances resolve to 10.2.1 ✓

$ pnpm build && pnpm test
# 18/18 tasks successful, 0 failures ✓

Test plan

🤖 Generated with Claude Code

Summary by CodeRabbit

  • Chores
    • Updated dependency override configurations to ensure consistent package versions across the project.

Dependabot alert #2: minimatch <10.2.1 has ReDoS via repeated wildcards.
Force-resolve all transitive minimatch instances to patched version
via pnpm.overrides. Only affects devDependencies (c8 coverage tool).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added the type:bug Bug report: something is not working as documented label Feb 20, 2026
@coderabbitai

coderabbitai Bot commented Feb 20, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉


📝 Walkthrough

Walkthrough

Adds a new pnpm override entry for minimatch version "10.2.1" to package.json alongside the existing ajv override, ensuring versions below 10.2.1 are resolved to 10.2.1.

Changes

Cohort / File(s) Summary
Dependencies
package.json
Introduces a new pnpm.overrides entry mapping minimatch@<10.2.1 to 10.2.1, preserving the existing ajv override configuration.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Suggested labels

dependencies

Poem

🐰 A little hop, a comma placed just right,
Minimatch now pinned with version might,
Dependencies aligned, no conflicts in sight,
Small change, big order—hopping with delight! ✨

🚥 Pre-merge checks | ✅ 3
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the main change: adding a dependency override for minimatch to fix a ReDoS vulnerability, which aligns perfectly with the changeset.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/minimatch-redos

Comment @coderabbitai help to get the list of available commands and usage tips.

@intech intech self-assigned this Feb 20, 2026
@pkg-pr-new

pkg-pr-new Bot commented Feb 20, 2026

Copy link
Copy Markdown

Open in StackBlitz

@connectum/auth

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/auth@33

@connectum/cli

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/cli@33

@connectum/core

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/core@33

@connectum/healthcheck

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/healthcheck@33

@connectum/interceptors

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/interceptors@33

@connectum/otel

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/otel@33

@connectum/reflection

npm i https://pkg.pr.new/Connectum-Framework/connectum/@connectum/reflection@33

commit: 96762e1

@intech
intech merged commit 385d881 into main Feb 20, 2026
10 checks passed
@intech
intech deleted the fix/minimatch-redos branch February 20, 2026 12:14
@coderabbitai coderabbitai Bot mentioned this pull request May 4, 2026
10 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Bug report: something is not working as documented

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant