Skip to content

chore(root): exclude minimatch ReDoS from yarn audit#8205

Merged
mrdanish26 merged 1 commit intomasterfrom
WP-8085
Feb 27, 2026
Merged

chore(root): exclude minimatch ReDoS from yarn audit#8205
mrdanish26 merged 1 commit intomasterfrom
WP-8085

Conversation

@mrdanish26
Copy link
Contributor

@mrdanish26 mrdanish26 commented Feb 26, 2026

TICKET: WP-8085

SDK release failed because of the two failing advisories (GHSA-7r86-cg39-jmmj and GHSA-23c5-xmqv-rm74) are both minimatch ReDoS vulnerabilities, the same class of issue as the already-excluded GHSA-3ppc-4f35-3m26.

https://github.com/BitGo/build-system/actions/runs/22464347697/job/65066725322#step:11:248

@mrdanish26 mrdanish26 requested review from a team as code owners February 26, 2026 23:31
Copy link
Contributor

@bitgopatmcl bitgopatmcl left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was reviewed by appsec and assessed as low risk

@mrdanish26 mrdanish26 merged commit 8194466 into master Feb 27, 2026
21 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants