fix(deps): patch picomatch to >= 4.0.4 (CVE-2026-33671)#332
Conversation
ReDoS via crafted extglob patterns causing catastrophic backtracking. Refs: CIP-2936
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughUpdated Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Patches picomatch ReDoS vulnerability via pnpm overrides:
Changes
picomatch@^4(>=4.0.4) andpicomatch@^2(>=2.3.2)pnpm-lock.yamlTest plan
pnpm why picomatchshows 4.0.4, no 4.0.2 or 4.0.3Refs: CIP-2936
Summary by CodeRabbit