Skip to content

Bump minimatch to sort 饾搾饾摜饾摂s - #1796

Merged
Krinkle merged 3 commits into
gruntjs:mainfrom
diegocr:patch-1
Apr 7, 2026
Merged

Krinkle merged 3 commits into
gruntjs:mainfrom
diegocr:patch-1

Conversation

@diegocr

@diegocr diegocr commented Mar 17, 2026

Copy link
Copy Markdown
Contributor

@tzahari

tzahari commented Mar 19, 2026

Copy link
Copy Markdown

Relates to /pull/1767

@diegocr

diegocr commented Mar 19, 2026

Copy link
Copy Markdown
Contributor Author

@tzahari that PR is bumping to v9, and i wonder if that isn't a breaking change 馃憖

@tzahari

tzahari commented Mar 19, 2026

Copy link
Copy Markdown

@tzahari that PR is bumping to v9, and i wonder if that isn't a breaking change 馃憖

The pull request #1767 is from 2023... my guess is that this is deprecated...

@diegocr

diegocr commented Mar 19, 2026

Copy link
Copy Markdown
Contributor Author

So... not really related? 馃槈

@danrossi

Copy link
Copy Markdown

I have merged here and is working for me. https://github.com/danrossi/grunt/tree/minimatch-fix

@diegocr

diegocr commented Mar 31, 2026

Copy link
Copy Markdown
Contributor Author

Yeah @danrossi, next we just need the main grunt repo updated and a new npm package version published.

But anyway... for the time being what i did is adding overrides: meganz/webclient@d00700c

@danrossi

Copy link
Copy Markdown

I did not know you can do that. I am including my branch for now. There is some other grunt contrib packages with problems also.

 "grunt": "github:danrossi/grunt#minimatch-fix",

@danrossi

Copy link
Copy Markdown

That overrides potentially works. I am not sure if its related to main grunt. But I get these errors I need to try and override also

npm warn deprecated osenv@0.1.5: This package is no longer supported.
npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated glob@7.1.7: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me

@danrossi

danrossi commented Mar 31, 2026 •

Copy link
Copy Markdown

In my grunt branch I get a tonne of these audits still so might need more fixing. Maybe we need to move to a different build system. I like grunt though. I do not like the idea of having base64 code randomly injected into bundles I send out because of these npm attacks and mess.

npm warn deprecated tap@16.3.10: Versions of tap before v18 are no longer maintained. Please upgrade.
npm warn deprecated osenv@0.1.5: This package is no longer supported.
npm warn deprecated inflight@1.0.6: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.
npm warn deprecated raw-body@1.1.7: No longer maintained. Please upgrade to a stable version.
npm warn deprecated @humanwhocodes/config-array@0.13.0: Use @eslint/config-array instead
npm warn deprecated rimraf@3.0.2: Rimraf versions prior to v4 are no longer supported
npm warn deprecated @humanwhocodes/object-schema@2.0.3: Use @eslint/object-schema instead
npm warn deprecated glob@7.1.7: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
npm warn deprecated libtap@1.4.1: This library is no longer used by node-tap, and is unmaintained.
npm warn deprecated eslint@8.57.1: This version is no longer supported. Please see https://eslint.org/version-support for other options.

added 498 packages, and audited 662 packages in 1m

138 packages are looking for funding
  run `npm fund` for details

I did a check update this may have api breaks. These are the versions I get.

 "dependencies": {
    "dateformat": "~5.0.3",
    "eventemitter2": "~6.4.9",
    "exit": "~0.1.2",
    "findup-sync": "~5.0.0",
    "glob": "~13.0.6",
    "grunt-cli": "^1.5.0",
    "grunt-known-options": "~2.0.0",
    "grunt-legacy-log": "~3.0.0",
    "grunt-legacy-util": "~2.0.1",
    "iconv-lite": "~0.7.2",
    "js-yaml": "~4.1.1",
    "minimatch": "~10.2.5",
    "nopt": "^9.0.0"
  },
  "devDependencies": {
    "difflet": "~1.0.1",
    "eslint-config-grunt": "~2.0.1",
    "grunt-contrib-nodeunit": "~5.0.0",
    "grunt-contrib-watch": "~1.1.0",
    "grunt-eslint": "~26.0.0",
    "temporary": "~1.1.0",
    "through2": "~4.0.2"
  },

After I did that there is a tonne of other stuff. So might need to use my branch or figure overrides.


# npm audit report

@babel/helpers  <7.26.10
Severity: moderate
Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups - https://github.com/advisories/GHSA-968p-4wvh-cqc8
fix available via `npm audit fix`
node_modules/tap/node_modules/@babel/helpers

ajv  <=6.12.6
Severity: moderate
Prototype Pollution in Ajv - https://github.com/advisories/GHSA-v88g-cgmw-v5xw
ajv has ReDoS when using `$data` option - https://github.com/advisories/GHSA-2g4f-4pwh-qvx6
fix available via `npm audit fix`
node_modules/table/node_modules/ajv
table  3.7.10 - 4.0.2
Depends on vulnerable versions of ajv
node_modules/table

brace-expansion  <=1.1.12
Severity: moderate
brace-expansion Regular Expression Denial of Service vulnerability - https://github.com/advisories/GHSA-v6h2-p8h4-qcjw
brace-expansion: Zero-step sequence causes process hang and memory exhaustion - https://github.com/advisories/GHSA-f886-m6hf-6m8v
fix available via `npm audit fix`
node_modules/tap/node_modules/brace-expansion

debug  <=2.6.8
Severity: high
debug Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-9vvw-cc9w-f27h
Regular Expression Denial of Service in debug - https://github.com/advisories/GHSA-gxpj-cx7g-858c
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/tiny-lr/node_modules/debug
tiny-lr  <=1.0.4
Depends on vulnerable versions of debug
Depends on vulnerable versions of qs
node_modules/tiny-lr
  grunt-contrib-watch  <=1.0.1
  Depends on vulnerable versions of gaze
  Depends on vulnerable versions of grunt
  Depends on vulnerable versions of tiny-lr
  node_modules/grunt-contrib-watch

getobject  0.1.0
Severity: critical
Prototype pollution in getobject - https://github.com/advisories/GHSA-957j-59c2-j692
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/grunt/node_modules/getobject
grunt  *
Depends on vulnerable versions of findup-sync
Depends on vulnerable versions of getobject
Depends on vulnerable versions of glob
Depends on vulnerable versions of grunt-legacy-log
Depends on vulnerable versions of grunt-legacy-util
Depends on vulnerable versions of js-yaml
Depends on vulnerable versions of lodash
Depends on vulnerable versions of minimatch
Depends on vulnerable versions of underscore.string
node_modules/grunt
grunt-legacy-util  <=2.0.0
Depends on vulnerable versions of getobject
Depends on vulnerable versions of lodash
Depends on vulnerable versions of underscore.string
node_modules/grunt/node_modules/grunt-legacy-util


js-yaml  <=3.14.1
Severity: high
Denial of Service in js-yaml - https://github.com/advisories/GHSA-2pr6-76vf-7546
Code Injection in js-yaml - https://github.com/advisories/GHSA-8j8c-7jfh-h6hx
js-yaml has prototype pollution in merge (<<) - https://github.com/advisories/GHSA-mh29-5h37-fv8m
Depends on vulnerable versions of argparse
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/grunt/node_modules/js-yaml

lodash  <=4.17.21
Severity: critical
Prototype Pollution in lodash - https://github.com/advisories/GHSA-fvqr-27wr-82fm
Command Injection in lodash - https://github.com/advisories/GHSA-35jh-r3h4-6jhm
Prototype Pollution in lodash - https://github.com/advisories/GHSA-4xc9-xhrj-v574
Prototype Pollution in lodash - https://github.com/advisories/GHSA-jf85-cpcp-j695
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions - https://github.com/advisories/GHSA-xxjr-mmjv-4gpg
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/grunt/node_modules/findup-sync/node_modules/lodash
node_modules/grunt/node_modules/grunt-legacy-log-utils/node_modules/lodash
node_modules/grunt/node_modules/grunt-legacy-log/node_modules/lodash
node_modules/lodash
node_modules/tap/node_modules/lodash
findup-sync  <=0.2.1
Depends on vulnerable versions of glob
Depends on vulnerable versions of lodash
node_modules/grunt/node_modules/findup-sync
grunt-legacy-log  <=1.0.2
Depends on vulnerable versions of grunt-legacy-log-utils
Depends on vulnerable versions of lodash
Depends on vulnerable versions of underscore.string
node_modules/grunt/node_modules/grunt-legacy-log
grunt-legacy-log-utils  <=1.0.0
Depends on vulnerable versions of lodash
Depends on vulnerable versions of underscore.string
node_modules/grunt/node_modules/grunt-legacy-log-utils

minimatch  <=3.1.3
Severity: high
Regular Expression Denial of Service in minimatch - https://github.com/advisories/GHSA-hxm2-r34f-qmc5
minimatch ReDoS vulnerability - https://github.com/advisories/GHSA-f8q6-p94x-37v3
minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern - https://github.com/advisories/GHSA-3ppc-4f35-3m26
minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments - https://github.com/advisories/GHSA-7r86-cg39-jmmj
minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regular expressions - https://github.com/advisories/GHSA-23c5-xmqv-rm74
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/fileset/node_modules/glob/node_modules/minimatch
node_modules/fileset/node_modules/minimatch
node_modules/gaze/node_modules/minimatch
node_modules/grunt/node_modules/findup-sync/node_modules/minimatch
node_modules/grunt/node_modules/minimatch
node_modules/tap/node_modules/minimatch
fileset  0.1.0 - 0.2.1
Depends on vulnerable versions of glob
Depends on vulnerable versions of minimatch
node_modules/fileset
  gaze  <=0.3.4
  Depends on vulnerable versions of fileset
  Depends on vulnerable versions of minimatch
  node_modules/gaze
glob  3.0.0 - 5.0.14
Depends on vulnerable versions of minimatch
node_modules/fileset/node_modules/glob
node_modules/grunt/node_modules/findup-sync/node_modules/glob
node_modules/grunt/node_modules/glob

qs  <=6.14.0
Severity: high
Prototype Pollution Protection Bypass in qs - https://github.com/advisories/GHSA-gqgv-6jq5-jjj9
Denial-of-Service Extended Event Loop Blocking in qs - https://github.com/advisories/GHSA-f9cm-p3w6-xvr3
Denial-of-Service Memory Exhaustion in qs - https://github.com/advisories/GHSA-jjv7-qpx3-h62q
qs vulnerable to Prototype Pollution - https://github.com/advisories/GHSA-hrpp-h998-j3pp
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion - https://github.com/advisories/GHSA-6rw7-vpxm-498p
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/qs

shelljs  <=0.8.4
Severity: high
Improper Privilege Management in shelljs - https://github.com/advisories/GHSA-64g7-mvw6-v9qj
Improper Privilege Management in shelljs - https://github.com/advisories/GHSA-4rq4-32rv-6wp6
fix available via `npm audit fix --force`
Will install grunt-eslint@26.0.0, which is a breaking change
node_modules/shelljs
eslint  1.4.0 - 4.0.0-rc.0
Depends on vulnerable versions of shelljs
node_modules/grunt-eslint/node_modules/eslint
  grunt-eslint  17.2.0 - 19.0.0
  Depends on vulnerable versions of eslint
  node_modules/grunt-eslint

underscore  <=1.13.7
Severity: critical
Arbitrary Code Execution in underscore - https://github.com/advisories/GHSA-cf4h-3jhx-xvhq
Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack - https://github.com/advisories/GHSA-qpx9-hpmf-5gmw
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/underscore
argparse  <=0.1.16
Depends on vulnerable versions of underscore
Depends on vulnerable versions of underscore.string
node_modules/grunt/node_modules/argparse

underscore.string  <3.3.5
Severity: moderate
Regular Expression Denial of Service in underscore.string - https://github.com/advisories/GHSA-v2p6-4mp7-3r9v
fix available via `npm audit fix --force`
Will install grunt-contrib-watch@1.1.0, which is a breaking change
node_modules/grunt/node_modules/argparse/node_modules/underscore.string
node_modules/grunt/node_modules/grunt-legacy-log-utils/node_modules/underscore.string
node_modules/grunt/node_modules/grunt-legacy-log/node_modules/underscore.string
node_modules/grunt/node_modules/underscore.string

ws  7.0.0 - 7.5.9
Severity: high
ws affected by a DoS when handling a request with many HTTP headers - https://github.com/advisories/GHSA-3h5v-q93c-6h6q
fix available via `npm audit fix`
node_modules/tap/node_modules/ws

yaml  1.0.0 - 1.10.2
Severity: moderate
yaml is vulnerable to Stack Overflow via deeply nested YAML collections - https://github.com/advisories/GHSA-48c2-rrv3-qjmp
fix available via `npm audit fix`
node_modules/tap/node_modules/yaml

28 vulnerabilities (10 moderate, 12 high, 6 critical)

@diegocr

diegocr commented Mar 31, 2026 •

Copy link
Copy Markdown
Contributor Author

I do also get several of alike deprecated warnings, which i do ignore.

Regarding the audit report, some work to do there indeed... and by using overrides you could sort some of these in a more easy way than creating forks for all of them, although i cannot assure you could resolve everything either way... that's certainly a very long list of vulnerabilities!

@danrossi

Copy link
Copy Markdown

I don't know what is going on. It seems alot of the circular dep issues is with dev packages. Here is a barebones override that gives me no warnings. I also had to update this package. It seems alot of these packages become unmaintained so have to fork them yourself. Or move to a different build system somehow.

https://github.com/danrossi/grunt-aws/blob/aws-sdk-v3/example/package.json#L2

@danrossi

danrossi commented Apr 7, 2026

Copy link
Copy Markdown

There is a tonne more issues with grunt now and getting worse. lodash is always targeted and shouldn't be used I reckon.

  grunt-legacy-log  >=1.0.1
  Depends on vulnerable versions of lodash
  node_modules/grunt-legacy-log
    grunt  >=1.0.0-rc1
    Depends on vulnerable versions of grunt-legacy-log
    Depends on vulnerable versions of grunt-legacy-util
    node_modules/grunt
      load-grunt-tasks  >=4.0.0
      Depends on vulnerable versions of grunt
      node_modules/load-grunt-tasks
  grunt-legacy-log-utils  1.0.0 - 2.1.0
  Depends on vulnerable versions of lodash
  node_modules/grunt-legacy-log-utils
  grunt-legacy-util  >=1.0.0-rc1
  Depends on vulnerable versions of lodash
  node_modules/grunt-legacy-util

@Krinkle

Krinkle commented Apr 7, 2026

Copy link
Copy Markdown
Member

@danrossi The lodash issue applies to the grunt-legacy-log package and is taken care of via gruntjs/grunt-legacy-log#35.

@Krinkle
Krinkle merged commit 662e097 into gruntjs:main Apr 7, 2026
10 checks passed
@mdeweeseCanaryLabs

Copy link
Copy Markdown

@Krinkle

1795

Is the process for cutting new releases documented?

Thank you.

@Krinkle

Krinkle commented Apr 7, 2026

Copy link
Copy Markdown
Member

@mdeweeseCanaryLabs Once gruntjs/grunt-legacy-util#48 and gruntjs/grunt-legacy-log#37 land, I'll do one more patch here to apply those (to fix the lodash audit warning) and then I'll propose a minor release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants