Update picomatch dependency to latest 4.0.4#53
Open
jdufresne wants to merge 1 commit into
Open
Conversation
This updates picomatch dependency to latest version 4.0.4. This helps projects that pull in anymatch, either directly or as a transient dependency, to have less duplication in node_modules as they are many other packages that also depend on picomatch.
|
This will also help consumers address this transitive vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2026-33672 (v2.3.2 would also address it) |
Contributor
|
^2 version selector in package.json will already use 2.3.2 when it’s available. upgrading to v4 will break backwards compat with some platforms because reqs change. If this is about chokidar, upgrade to latest chokidar across your deps instead. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This updates picomatch dependency to latest version 4.0.4. This helps projects that pull in anymatch, either directly or as a transient dependency, to have less duplication in node_modules as there are many other packages that also depend on picomatch.