Skip to content

security(deps): VPR-35 Update glob/yaml/minimatch - #71

Merged
rlorenzo merged 1 commit into
mainfrom
VPR-35-update-glob-yaml
Nov 19, 2025
Merged

rlorenzo merged 1 commit into
mainfrom
VPR-35-update-glob-yaml

Conversation

@rlorenzo

Copy link
Copy Markdown
Contributor
  • Update glob from 11.0.3 to 11.1.0 (fixes high severity command injection CVE)
  • Update js-yaml from 4.1.0 to 4.1.1 (fixes moderate prototype pollution)
  • Update minimatch from 10.0.3 to 10.1.1 (bug fixes for regex generation edge cases)
  • Configure Jenkins audit to omit dev dependencies from security scan

- Update glob from 11.0.3 to 11.1.0 (fixes high severity command injection CVE)
- Update js-yaml from 4.1.0 to 4.1.1 (fixes moderate prototype pollution)
- Update minimatch from 10.0.3 to 10.1.1 (bug fixes for regex
  generation edge cases)
- Configure Jenkins audit to omit dev dependencies from security scan
Copilot AI review requested due to automatic review settings November 19, 2025 18:57

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates several npm packages to address security vulnerabilities and improve package security posture. The main focus is updating glob to fix a high severity command injection CVE, updating js-yaml to address prototype pollution, and updating minimatch for regex generation bug fixes.

  • Updated glob from 11.0.3 to 11.1.0 (production dependency in VueApp)
  • Updated js-yaml from 4.1.0 to 4.1.1 across both package-lock.json files
  • Updated minimatch from 10.0.3 to 10.1.1 as a dependency of glob
  • Modified Jenkins audit configuration to exclude dev dependencies from security scans

Reviewed Changes

Copilot reviewed 1 out of 3 changed files in this pull request and generated no comments.

File Description
VueApp/package-lock.json Updates glob (main package and nested versions), minimatch, and js-yaml dependencies with new versions and integrity hashes; includes license updates from ISC to BlueOak-1.0.0 for glob and minimatch
package-lock.json Updates js-yaml from 4.1.0 to 4.1.1 with corresponding integrity hash
JenkinsFile Adds --omit=dev flag to npm audit command to exclude development dependencies from security scanning
Files not reviewed (1)
  • VueApp/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@rlorenzo

Copy link
Copy Markdown
Contributor Author

@bsedwards The package updates are mainly for our dev tools:

  1. glob (11.0.3 → 11.1.0)
  • Fix: CVE-2025-64756 command injection in CLI
  • Impact: None - We use glob programmatically via build tools, not the CLI
  • Affected by vulnerability: No - Only affects CLI usage with user-controlled filenames
  1. js-yaml (4.1.0 → 4.1.1)
  • Fix: Prototype pollution in YAML merge operator
  • Impact: None - We don't use YAML merge operations
  • Affected by vulnerability: No - Only affects code parsing YAML with << merge keys
  1. minimatch (10.0.3 → 10.1.1)
  • Fix: Bug fixes for regex generation edge cases
  • Impact: None - Internal glob pattern matching improvements
  • Changes: Fixed makeRe() behavior with partial: true and trailing ** patterns

@rlorenzo
rlorenzo requested a review from bsedwards November 19, 2025 19:01
@rlorenzo
rlorenzo merged commit 7053c34 into main Nov 19, 2025
11 checks passed
@rlorenzo
rlorenzo deleted the VPR-35-update-glob-yaml branch November 19, 2025 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants