Skip to content

Commit 219f444

Browse files
committed
🔒️(secu) fix CVE-2026-26996 with minimatch
We get a warning about a vulnerability in minimatch 3.1.2. We ugrade to 10.2.1 to fix the issue.
1 parent 010ed46 commit 219f444

File tree

2 files changed

+16
-42
lines changed

2 files changed

+16
-42
lines changed

src/frontend/package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@
3636
"@types/react": "19.2.8",
3737
"@types/react-dom": "19.2.3",
3838
"eslint": "9.39.2",
39+
"minimatch": "10.2.1",
3940
"prosemirror-view": "1.41.4",
4041
"react": "19.2.3",
4142
"react-dom": "19.2.3",

src/frontend/yarn.lock

Lines changed: 15 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -8301,16 +8301,16 @@ bail@^2.0.0:
83018301
resolved "https://registry.yarnpkg.com/bail/-/bail-2.0.2.tgz#d26f5cd8fe5d6f832a31517b9f7c356040ba6d5d"
83028302
integrity sha512-0xO6mYd7JB2YesxDKplafRpsiOzPt9V02ddPCLbY1xYGPOX24NTyN50qnUxgCPcSoYMhKpAuBTjQoRZCAkUDRw==
83038303

8304-
balanced-match@^1.0.0:
8305-
version "1.0.2"
8306-
resolved "https://registry.yarnpkg.com/balanced-match/-/balanced-match-1.0.2.tgz#e83e3a7e3f300b34cb9d87f615fa0cbf357690ee"
8307-
integrity sha512-3oSeUO0TMV67hN1AmbXsK4yaqU7tjiHlbxRDZOpH0KW9+CeX4bRAaX0Anxt0tx2MrpRpWwQaPwIlISEJhYU5Pw==
8308-
83098304
balanced-match@^2.0.0:
83108305
version "2.0.0"
83118306
resolved "https://registry.yarnpkg.com/balanced-match/-/balanced-match-2.0.0.tgz#dc70f920d78db8b858535795867bf48f820633d9"
83128307
integrity sha512-1ugUSr8BHXRnK23KfuYS+gVMC3LB8QGH9W1iGtDPsNWoQbgtXSExkBu2aDR4epiGWZOjZsj6lDl/N/AqqTC3UA==
83138308

8309+
balanced-match@^4.0.2:
8310+
version "4.0.3"
8311+
resolved "https://registry.yarnpkg.com/balanced-match/-/balanced-match-4.0.3.tgz#6337a2f23e0604a30481423432f99eac603599f9"
8312+
integrity sha512-1pHv8LX9CpKut1Zp4EXey7Z8OfH11ONNH6Dhi2WDUt31VVZFXZzKwXcysBgqSumFCmR+0dqjMK5v5JiFHzi0+g==
8313+
83148314
bare-events@^2.7.0:
83158315
version "2.8.0"
83168316
resolved "https://registry.yarnpkg.com/bare-events/-/bare-events-2.8.0.tgz#ec962fa9e2bfafd4edd444942df1ed0c7aba8e4a"
@@ -8382,20 +8382,12 @@ boolbase@^1.0.0:
83828382
resolved "https://registry.yarnpkg.com/boolbase/-/boolbase-1.0.0.tgz#68dff5fbe60c51eb37725ea9e3ed310dcc1e776e"
83838383
integrity sha512-JZOSA7Mo9sNGB8+UjSgzdLtokWAky1zbztM3WRLCbZ70/3cTANmQmOdR7y2g+J0e2WXywy1yS468tY+IruqEww==
83848384

8385-
brace-expansion@^1.1.7:
8386-
version "1.1.12"
8387-
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-1.1.12.tgz#ab9b454466e5a8cc3a187beaad580412a9c5b843"
8388-
integrity sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==
8389-
dependencies:
8390-
balanced-match "^1.0.0"
8391-
concat-map "0.0.1"
8392-
8393-
brace-expansion@^2.0.1:
8394-
version "2.0.2"
8395-
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-2.0.2.tgz#54fc53237a613d854c7bd37463aad17df87214e7"
8396-
integrity sha512-Jt0vHyM+jmUBqojB7E1NIYadt0vI0Qxjxd2TErW94wDz+E2LAm5vKMXXwg6ZZBTHPuUlDgQHKXvjGBdfcF1ZDQ==
8385+
brace-expansion@^5.0.2:
8386+
version "5.0.2"
8387+
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-5.0.2.tgz#b6c16d0791087af6c2bc463f52a8142046c06b6f"
8388+
integrity sha512-Pdk8c9poy+YhOgVWw1JNN22/HcivgKWwpxKq04M/jTmHyCZn12WPJebZxdjSa5TmBqISrUSgNYU3eRORljfCCw==
83978389
dependencies:
8398-
balanced-match "^1.0.0"
8390+
balanced-match "^4.0.2"
83998391

84008392
braces@^3.0.3, braces@~3.0.2:
84018393
version "3.0.3"
@@ -8849,11 +8841,6 @@ compute-scroll-into-view@^3.1.0:
88498841
resolved "https://registry.yarnpkg.com/compute-scroll-into-view/-/compute-scroll-into-view-3.1.1.tgz#02c3386ec531fb6a9881967388e53e8564f3e9aa"
88508842
integrity sha512-VRhuHOLoKYOy4UbilLbUzbYg93XLjv2PncJC50EuTWPA3gaja1UjBsUP/D/9/juV3vQFr6XBEzn9KCAHdUvOHw==
88518843

8852-
concat-map@0.0.1:
8853-
version "0.0.1"
8854-
resolved "https://registry.yarnpkg.com/concat-map/-/concat-map-0.0.1.tgz#d8a96bd77fd68df7793a73036a3ba0d5405d477b"
8855-
integrity sha512-/Srv4dswyQNBfohGpz9o6Yb3Gz3SrUDqBH5rTuhGR7ahtlbYKnVxw2bCFMRljaA7EXHaXZ8wsHdodFvbkhKmqg==
8856-
88578844
content-disposition@^1.0.0:
88588845
version "1.0.0"
88598846
resolved "https://registry.yarnpkg.com/content-disposition/-/content-disposition-1.0.0.tgz#844426cb398f934caefcbb172200126bc7ceace2"
@@ -13059,26 +13046,12 @@ minimalistic-assert@^1.0.1:
1305913046
resolved "https://registry.yarnpkg.com/minimalistic-assert/-/minimalistic-assert-1.0.1.tgz#2e194de044626d4a10e7f7fbc00ce73e83e4d5c7"
1306013047
integrity sha512-UtJcAD4yEaGtjPezWuO9wC4nwUnVH/8/Im3yEHQP4b67cXlD/Qr9hdITCU1xDbSEXg2XKNaP8jsReV7vQd00/A==
1306113048

13062-
minimatch@^3.0.2, minimatch@^3.0.4, minimatch@^3.1.1, minimatch@^3.1.2:
13063-
version "3.1.2"
13064-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-3.1.2.tgz#19cd194bfd3e428f049a70817c038d89ab4be35b"
13065-
integrity sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==
13066-
dependencies:
13067-
brace-expansion "^1.1.7"
13068-
13069-
minimatch@^5.0.1:
13070-
version "5.1.6"
13071-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-5.1.6.tgz#1cfcb8cf5522ea69952cd2af95ae09477f122a96"
13072-
integrity sha512-lKwV/1brpG6mBUFHtb7NUmtABCb2WZZmm2wNiOA5hAb8VdCS4B3dtMWyvcoViccwAW/COERjXLt0zP1zXUN26g==
13073-
dependencies:
13074-
brace-expansion "^2.0.1"
13075-
13076-
minimatch@^9.0.0, minimatch@^9.0.4, minimatch@^9.0.5:
13077-
version "9.0.5"
13078-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-9.0.5.tgz#d74f9dd6b57d83d8e98cfb82133b03978bc929e5"
13079-
integrity sha512-G6T0ZX48xgozx7587koeX9Ys2NYy6Gmv//P89sEte9V9whIapMNF4idKxnW2QtCcLiTWlb/wfCabAtAFWhhBow==
13049+
minimatch@10.2.1, minimatch@^3.0.2, minimatch@^3.0.4, minimatch@^3.1.1, minimatch@^3.1.2, minimatch@^5.0.1, minimatch@^9.0.0, minimatch@^9.0.4, minimatch@^9.0.5:
13050+
version "10.2.1"
13051+
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-10.2.1.tgz#9d82835834cdc85d5084dd055e9a4685fa56e5f0"
13052+
integrity sha512-MClCe8IL5nRRmawL6ib/eT4oLyeKMGCghibcDWK+J0hh0Q8kqSdia6BvbRMVk6mPa6WqUa5uR2oxt6C5jd533A==
1308013053
dependencies:
13081-
brace-expansion "^2.0.1"
13054+
brace-expansion "^5.0.2"
1308213055

1308313056
minimist@^1.2.0, minimist@^1.2.5, minimist@^1.2.6:
1308413057
version "1.2.8"

0 commit comments

Comments
 (0)