New fast-glob version required due to dependency CVE in micromatch
envgap__mrmlnc__fast-glob-443
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
1e520c174e225b3ecdeced7283a05fcb002d1033- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
mrmlnc/fast-glob #443 · read the original issue
Hello, could you please provide a rebuild / new version from fast-glob to bump to new micromatch dependency version 4.0.6 fast-glob 3.3.2 defines a dependency to micromatch. ├─┬ [fast-glob@3.3.2](mailto:fast-glob@3.3.2) │ │ ├── [@nodelib/fs.stat@2.0.5](https://github.com/ccm/users/nodelib/fs.stat@2.0.5) │ │ ├── [@nodelib/fs.walk@1.2.8](https://github.com/ccm/users/nodelib/fs.walk@1.2.8) deduped │ │ ├─┬ [glob-parent@5.1.2](mailto:glob-parent@5.1.2) │ │ │ └── [is-glob@4.0.3](mailto:is-glob@4.0.3) deduped │ │ ├── [merge2@1.4.1](mailto:merge2@1.4.1) │ │ └─┬ [micromatch@4.0.5](mailto:micromatch@4.0.5) How to fix? Upgrade micromatch to version 4.0.6 or higher. See: https://security.snyk.io/vuln/SNYK-JS-MICROMATCH-6838728 Thanks.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]