Skip to content

Bump minimatch 10.2.2 → 10.2.4 in azure-sdk-qa-bot-function#14345

Draft
Copilot wants to merge 2 commits intomainfrom
copilot/bump-minimatch-version
Draft

Bump minimatch 10.2.2 → 10.2.4 in azure-sdk-qa-bot-function#14345
Copilot wants to merge 2 commits intomainfrom
copilot/bump-minimatch-version

Conversation

Copy link
Contributor

Copilot AI commented Mar 4, 2026

Bumps transitive minimatch dependency to latest (10.2.4) to address CVE-2026-27904 (catastrophic regex backtracking).

  • Lockfile-only change via npm update minimatch --package-lock-only
  • No direct dependency or package.json changes

🔒 GitHub Advanced Security automatically protects Copilot coding agent pull requests. You can protect all pull requests by enabling Advanced Security for your repositories. Learn more about Advanced Security.

Co-authored-by: mikeharder <9459391+mikeharder@users.noreply.github.com>
Copilot AI changed the title [WIP] Update minimatch to latest version in package-lock.json Bump minimatch 10.2.2 → 10.2.4 in azure-sdk-qa-bot-function Mar 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants