fix: update vulnerable dependency picomatch #43

Closed
opened 2026-03-30 00:44:27 +00:00 by maximus · 0 comments
Owner

Vulnerability detected by defenseur-simpl

The following HIGH severity vulnerability was flagged:

Package Severity Current Fix
picomatch (x2) HIGH 4.0.3 4.0.4

Vulnérabilités

Analyse

  • Dépendance transitive de vite@6.4.1 (via fdir, tinyglobby, et direct)
  • Pas une dépendance directe du projet
  • Les ranges existantes (^4.0.2, ^4.0.3) acceptent 4.0.4

Plan (Option A)

  • npm audit fix pour mettre à jour picomatch 4.0.3 → 4.0.4
  • Vérifier npm audit clean
  • Vérifier npm run build OK

Fichiers concernés

  • package-lock.json uniquement

Critères d'acceptation

  • npm audit retourne 0 vulnérabilité picomatch
  • npm run build réussit
  • Aucun changement dans package.json

Complexité

Simple


Source: defenseur-simpl security scan

## Vulnerability detected by defenseur-simpl The following HIGH severity vulnerability was flagged: | Package | Severity | Current | Fix | |---|---|---|---| | **picomatch** (x2) | HIGH | 4.0.3 | 4.0.4 | ### Vulnérabilités - [GHSA-3v7f-55p6-f55p](https://github.com/advisories/GHSA-3v7f-55p6-f55p) — Method Injection in POSIX Character Classes - [GHSA-c2c7-rcm5-vvqj](https://github.com/advisories/GHSA-c2c7-rcm5-vvqj) — ReDoS via extglob quantifiers ### Analyse - Dépendance transitive de `vite@6.4.1` (via `fdir`, `tinyglobby`, et direct) - Pas une dépendance directe du projet - Les ranges existantes (`^4.0.2`, `^4.0.3`) acceptent 4.0.4 ### Plan (Option A) - [ ] `npm audit fix` pour mettre à jour picomatch 4.0.3 → 4.0.4 - [ ] Vérifier `npm audit` clean - [ ] Vérifier `npm run build` OK ### Fichiers concernés - `package-lock.json` uniquement ### Critères d'acceptation - [ ] `npm audit` retourne 0 vulnérabilité picomatch - [ ] `npm run build` réussit - [ ] Aucun changement dans `package.json` ### Complexité Simple --- _Source: defenseur-simpl security scan_
maximus added the
status:ready
type:bug
labels 2026-03-30 01:03:42 +00:00
maximus added
status:review
and removed
status:ready
labels 2026-03-30 01:10:04 +00:00
maximus added
status:approved
and removed
status:review
labels 2026-03-30 01:11:31 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: maximus/Simpl-Resultat#43
No description provided.