Repository navigation
Bump minimatch to sort 饾搾饾摜饾摂s - #1796
Conversation
|
Relates to /pull/1767 |
|
@tzahari that PR is bumping to v9, and i wonder if that isn't a breaking change 馃憖 |
|
So... not really related? 馃槈 |
|
I have merged here and is working for me. https://github.com/danrossi/grunt/tree/minimatch-fix |
|
Yeah @danrossi, next we just need the main grunt repo updated and a new npm package version published. But anyway... for the time being what i did is adding overrides: meganz/webclient@d00700c |
|
I did not know you can do that. I am including my branch for now. There is some other grunt contrib packages with problems also. |
|
That overrides potentially works. I am not sure if its related to main grunt. But I get these errors I need to try and override also |
|
In my grunt branch I get a tonne of these audits still so might need more fixing. Maybe we need to move to a different build system. I like grunt though. I do not like the idea of having base64 code randomly injected into bundles I send out because of these npm attacks and mess. I did a check update this may have api breaks. These are the versions I get. After I did that there is a tonne of other stuff. So might need to use my branch or figure overrides. |
|
I do also get several of alike Regarding the |
|
I don't know what is going on. It seems alot of the circular dep issues is with dev packages. Here is a barebones override that gives me no warnings. I also had to update this package. It seems alot of these packages become unmaintained so have to fork them yourself. Or move to a different build system somehow. https://github.com/danrossi/grunt-aws/blob/aws-sdk-v3/example/package.json#L2 |
|
There is a tonne more issues with grunt now and getting worse. lodash is always targeted and shouldn't be used I reckon. |
Allow for future updates to 3.2 if needed.
|
@danrossi The lodash issue applies to the |
|
@mdeweeseCanaryLabs Once gruntjs/grunt-legacy-util#48 and gruntjs/grunt-legacy-log#37 land, I'll do one more patch here to apply those (to fix the lodash audit warning) and then I'll propose a minor release. |
https://nvd.nist.gov/vuln/detail/CVE-2026-27903
https://nvd.nist.gov/vuln/detail/CVE-2026-27904
https://nvd.nist.gov/vuln/detail/CVE-2026-26996
Cheers.. 馃檹馃徎 馃憖