Fix minimatch security audit - #648
Conversation
melroy89
commented
Feb 27, 2026
|
It will be really good to have this merged |
I agree of course.. |
|
@isaacs - Any change this could get merged, pretty please? |
|
Hi, with the last audit errors, the idea is use |
|
Do package managers not update transitive deps with an update command anymore? What the hell. The update is allowed by the server range. These noisy PRs and pleading comments are super annoying. Go tell your package manager to do its job. |
|
I’m 100% not going to accept a PR that updates the lock file and nothing else. That is a giant pile of red flags. |
No they don't. Especially not when there is a dependency of a dependency. And/or when you use pnpm etc. Not sure why the lock file is part of the npm package (git repo is fine of course). |
Have you tried running
It's not. |