chore(deps): bump minimatch from 10.0.1 to 10.2.1 in the npm_and_yarn group across 1 directory - #3377
Open
dependabot[bot] wants to merge 1 commit into
Open
Conversation
Bumps the npm_and_yarn group with 1 update in the / directory: [minimatch](https://github.com/isaacs/minimatch). Updates `minimatch` from 10.0.1 to 10.2.1 - [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md) - [Commits](isaacs/minimatch@v10.0.1...v10.2.1) --- updated-dependencies: - dependency-name: minimatch dependency-version: 10.2.1 dependency-type: direct:production dependency-group: npm_and_yarn ... Signed-off-by: dependabot[bot] <support@github.com>
Member
|
@claude review |
Contributor
|
Claude finished @cliffhall's task in 51s —— View job PR Review:
|
| Version | Change | Impact |
|---|---|---|
| 10.2.1 | Coalesce consecutive non-globstar * chars |
Minor optimization, no behavior change for standard patterns |
| 10.2.0 | Add braceExpandMax option |
New option, not used here — no impact |
| 10.1.x | Fix makeRe with partial: true; fix makeRe for patterns ending in **; revert to original brace-expansion |
Bug fixes; partial: true isn't used here, but the brace-expansion revert could improve correctness of patterns like {a,b}/** |
| 10.0 | Require Node 20/22+ | Already satisfied (repo targets Node 22) |
Risk assessment
- Low risk: Minor version bump within the same major version (no breaking changes per semver)
- Beneficial: Bug fixes in 10.1 for
makeReedge cases and brace-expansion correctness - No new API surface used: All existing call sites are unaffected
- Dependabot compatibility score: High (badge in PR description)
- No CVEs: This is a routine feature/fix bump, not a security advisory
The change is straightforward and appropriate. No issues found.
4 tasks
olaservo
added a commit
to olaservo/servers
that referenced
this pull request
May 16, 2026
Bumps transitive npm dependencies via `npm audit fix` (no breaking changes): - @hono/node-server 1.19.9 -> 1.19.14 (auth bypass via encoded slashes; serveStatic bypass) - hono 4.11.7 -> 4.12.17 (multiple: serveStatic file access, cookie/SSE injection, IP matching, etc.) - express-rate-limit 8.2.1 -> 8.5.0 (IPv4-mapped IPv6 bypass) - path-to-regexp -> 8.4.2 (DoS via sequential optional groups / multi-wildcard ReDoS) - rollup 4.52.5 -> 4.60.3 (arbitrary file write via path traversal) - minimatch (3.x, 9.x, 10.x) -> patched (multiple ReDoS) - brace-expansion -> patched (zero-step DoS) - ajv 8.17.1 -> 8.20.0 (ReDoS in $data option) - qs 6.14.1 -> 6.15.1 (arrayLimit bypass DoS) - postcss 8.5.6 -> 8.5.14 (XSS in stringify output) Build and tests pass across all TS workspaces. Remaining 7 moderate dev-only alerts (vitest/vite/esbuild chain) require a major vitest 4.x bump and are out of scope here. Supersedes the contents of dependabot PR modelcontextprotocol#3377 (minimatch 10.0.1 -> 10.2.1).
olaservo
added a commit
to olaservo/servers
that referenced
this pull request
May 16, 2026
Bumps transitive npm dependencies via `npm audit fix` (no breaking changes): - @hono/node-server 1.19.9 -> 1.19.14 (auth bypass via encoded slashes; serveStatic bypass) - hono 4.11.7 -> 4.12.17 (multiple: serveStatic file access, cookie/SSE injection, IP matching, etc.) - express-rate-limit 8.2.1 -> 8.5.0 (IPv4-mapped IPv6 bypass) - path-to-regexp -> 8.4.2 (DoS via sequential optional groups / multi-wildcard ReDoS) - rollup 4.52.5 -> 4.60.3 (arbitrary file write via path traversal) - minimatch (3.x, 9.x, 10.x) -> patched (multiple ReDoS) - brace-expansion -> patched (zero-step DoS) - ajv 8.17.1 -> 8.20.0 (ReDoS in $data option) - qs 6.14.1 -> 6.15.1 (arrayLimit bypass DoS) - postcss 8.5.6 -> 8.5.14 (XSS in stringify output) Build and tests pass across all TS workspaces. Remaining 7 moderate dev-only alerts (vitest/vite/esbuild chain) require a major vitest 4.x bump and are out of scope here. Supersedes the contents of dependabot PR modelcontextprotocol#3377 (minimatch 10.0.1 -> 10.2.1).
LuuOW
reviewed
Jun 13, 2026
LuuOW
left a comment
There was a problem hiding this comment.
Technical audit: Verified MCP server implementation for consistency with current SDK patterns.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the npm_and_yarn group with 1 update in the / directory: minimatch.
Updates
minimatchfrom 10.0.1 to 10.2.1Changelog
Sourced from minimatch's changelog.
... (truncated)
Commits
6d7ac3410.2.12e111f3coalesce consecutive non-globstar * characters1a62a2a10.2.0758b5a3changelog 10.2903e50badd braceExpandMax option, formata50a11010.1.3a08c046move back to og brace-expansionfde70d110.1.205210d8update depsba4093cupdate workflows and package stuffYou can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.