Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High vulnerability in 'braces' dependency #1416

Closed
apptio-mrejdych opened this issue May 15, 2024 · 3 comments · Fixed by #1418
Closed

High vulnerability in 'braces' dependency #1416

apptio-mrejdych opened this issue May 15, 2024 · 3 comments · Fixed by #1418

Comments

@apptio-mrejdych
Copy link

Hey Team
Snyk found high vulnerability in your package connected to 'braces' dependency

https://security.snyk.io/vuln/SNYK-JS-BRACES-6838727
https://www.cve.org/CVERecord?id=CVE-2024-4068

Is there any chance to fix it?

@iiroj
Copy link
Member

iiroj commented May 15, 2024

We don't use braces directly but through micromatch. Can you report the vulnerability there so that we can fix it once micromatch is updated?

@apptio-mrejdych
Copy link
Author

Sure. Thank you

@BellaMay95
Copy link

Hello all -- looks like micromatch version 4.0.6 fixes this issue, the lint-staged library can now be updated with this new version of micromatch to fix the vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging a pull request may close this issue.

3 participants