Skip to content

Update Socket patches: +3 patches - #8327

Open
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551806452-64b848d8
Open

Update Socket patches: +3 patches#8327
socket-security[bot] wants to merge 1 commit into
mainfrom
socket/autopatch-1786551806452-64b848d8

Conversation

@socket-security

Copy link
Copy Markdown

Summary

This PR updates Socket security patches for your dependencies.

These patches are applied via the Socket patch agent — .socket/manifest.json + a package.json postinstall hook.

Changes

  • Added: CVE-2022-3517 in pkg:npm/minimatch@3.0.4 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch ReDoS vulnerability
  • Added: CVE-2026-26996 in pkg:npm/minimatch@3.0.4 (Socket Patch)
    • Severity: HIGH
    • Summary: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
  • Added: CVE-2022-2900 in pkg:npm/parse-url@6.0.5 (Socket Patch)
    • Severity: CRITICAL
    • Summary: Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url

Testing

Review the patches and test your application to ensure compatibility.


🔒 Powered by Socket Security

Updates:
- 2 blob(s) added
- 0 blob(s) removed
- Manifest updated
@vercel

vercel Bot commented Aug 12, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
webpack-js-org Ready Ready Preview Aug 12, 2026 4:25pm

Request Review

@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@github-actions

Copy link
Copy Markdown

👋 Hi there! This PR was automatically flagged and closed by our quality checks.

If you believe this was a mistake, please review our contributing guidelines
and leave a comment explaining why this is a mistake.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant