Skip to content

Transitive vuln: brace-expansion@2.0.2 via @vue/language-cor -> minimatch #466

@AbhaysinghBhosale

Description

@AbhaysinghBhosale

Describe the bug

Vulnerability reported in vite-plugin-dts@4.5.4 which is coming from transitive dependancy "brace-expansion"

└─┬ vite-plugin-dts@4.5.4
└─┬ @vue/language-core@2.2.0
└─┬ minimatch@9.0.5
└── brace-expansion@2.0.2

Reproduction

https://security.snyk.io/package/npm/brace-expansion

Steps to reproduce

No response

System Info

Browser Chrome
Package - vite-plugin-dts@4.5.4

Validations

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions