From 3b50b7bcae27951a069c48220b7d3dc25f6fbab7 Mon Sep 17 00:00:00 2001 From: "opensearch-trigger-bot[bot]" <98922864+opensearch-trigger-bot[bot]@users.noreply.github.com> Date: Fri, 28 Oct 2022 16:38:36 -0700 Subject: [PATCH] [Security] Bump minimatch to 3.1.2 to fix the ReDoS vulnerability (#354) (#356) Signed-off-by: Zilong Xia Signed-off-by: Zilong Xia (cherry picked from commit 5cbaf2ed5af61df15e76b2bce0226ebb4c951868) Co-authored-by: ZilongX <99905560+ZilongX@users.noreply.github.com> --- package-lock.json | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/package-lock.json b/package-lock.json index ecc508d7d..179979719 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1974,9 +1974,9 @@ "dev": true }, "minimatch": { - "version": "3.0.4", - "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.0.4.tgz", - "integrity": "sha512-yJHVQEhyqPLUTgt9B83PXu6W3rx4MvvHvSUvToogpwoGDOUQ+yDrR0HRot+yOCdCO7u4hX3pWft6kWBBcqh0UA==", + "version": "3.1.2", + "resolved": "https://registry.npmjs.org/minimatch/-/minimatch-3.1.2.tgz", + "integrity": "sha512-J7p63hRiAjw1NDEww1W7i37+ByIrOWO5XQQAzZ3VOcL0PNybwpfmV/N05zFAzwQ9USyEcX6t3UO+K5aqBQOIHw==", "dev": true, "requires": { "brace-expansion": "^1.1.7"