Skip to content

Fix Dependabot alerts: undici, minimatch#174

Open
noahd1 wants to merge 1 commit intomainfrom
fix/dependabot-batch-2026-03-16
Open

Fix Dependabot alerts: undici, minimatch#174
noahd1 wants to merge 1 commit intomainfrom
fix/dependabot-batch-2026-03-16

Conversation

@noahd1
Copy link
Copy Markdown
Member

@noahd1 noahd1 commented Mar 16, 2026

Update @actions/* dependencies to resolve 20 Dependabot security alerts:

  • @actions/core: ^1.11.1 → ^2.0.3
  • @actions/exec: ^1.1.1 → ^2.0.0
  • @actions/github: ^6.0.0 → ^8.0.1
  • @actions/glob: ^0.5.0 → ^0.5.1
  • @actions/tool-cache: ^2.0.2 → ^3.0.1

Resolves:

  • undici@5.29.0 → 6.24.1 (GHSA-v9p9, GHSA-vrm6, GHSA-4992, GHSA-2mjp)
  • minimatch@3.1.2 → 3.1.5 (GHSA-23c5, GHSA-7r86)
  • minimatch@9.0.5 → 9.0.9 (GHSA-7r86)

Update @actions/* dependencies to resolve 20 Dependabot security alerts:

- @actions/core: ^1.11.1 → ^2.0.3
- @actions/exec: ^1.1.1 → ^2.0.0
- @actions/github: ^6.0.0 → ^8.0.1
- @actions/glob: ^0.5.0 → ^0.5.1
- @actions/tool-cache: ^2.0.2 → ^3.0.1

Resolves:
- undici@5.29.0 → 6.24.1 (GHSA-v9p9, GHSA-vrm6, GHSA-4992, GHSA-2mjp)
- minimatch@3.1.2 → 3.1.5 (GHSA-23c5, GHSA-7r86)
- minimatch@9.0.5 → 9.0.9 (GHSA-7r86)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@qltysh
Copy link
Copy Markdown
Contributor

qltysh Bot commented Mar 16, 2026

Qlty

Coverage Impact

This PR will not change total coverage.

🚦 See full report on Qlty Cloud »

🛟 Help
  • Diff Coverage: Coverage for added or modified lines of code (excludes deleted files). Learn more.

  • Total Coverage: Coverage for the whole repository, calculated as the sum of all File Coverage. Learn more.

  • File Coverage: Covered Lines divided by Covered Lines plus Missed Lines. (Excludes non-executable lines including blank lines and comments.)

    • Indirect Changes: Changes to File Coverage for files that were not modified in this PR. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant