Conversation
Updates pnpm override for minimatch from >=10.2.1 to >=10.2.3 (resolved to 10.2.4), addressing CVE-2026-27903 and CVE-2026-27904 (both High). Refs: CIP-2803
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review infoConfiguration used: defaults Review profile: CHILL Plan: Pro ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughUpdated the minimatch dependency constraint in pnpm overrides from version ">=10.2.1" to ">=10.2.3" in package.json. This is a patch-level version bump for dependency resolution. Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
minimatchfrom>=10.2.1to>=10.2.3(resolved to 10.2.4)CVEs
Test plan
Refs: CIP-2803
Summary by CodeRabbit
Note: This release contains no user-facing changes. Updates are maintenance-focused.