•  
      request #47545 Picomatch: 2.3.1 -> 2.3.2, 4.0.3 -> 4.0.4
    Infos
    #47545
    Thomas Gerbet (tgerbet)
    2026-03-26 12:46
    2026-03-26 10:04
    49268
    Details
    Picomatch: 2.3.1 -> 2.3.2, 4.0.3 -> 4.0.4

    Fixes CVE-2026-33672 and CVE-2026-33671. No real impact in Tuleap use cases, it is either running within dev tools with trusted inputs or in situations that cannot trigger the issues.

    https://github.com/micromatch/picomatch/releases/tag/4.0.4
    https://github.com/micromatch/picomatch/releases/tag/2.3.2

    Empty
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2026-03-26
    Attachments
    Empty
    References
    Referenced by request #47545

    Follow-ups