Skip to content

Upgrade minimatch in spelling package-lock.json#7055

Open
mohamed-zaki-coding wants to merge 1 commit intoAzure:feature/websocket_speechfrom
mohamed-zaki-coding:fix/upgrade-minimatch-package
Open

Upgrade minimatch in spelling package-lock.json#7055
mohamed-zaki-coding wants to merge 1 commit intoAzure:feature/websocket_speechfrom
mohamed-zaki-coding:fix/upgrade-minimatch-package

Conversation

@mohamed-zaki-coding
Copy link
Copy Markdown
Member

Summary

Upgrades the minimatch dependency in eng/common/spelling/package-lock.json to fix CVE-2026-27903 and CVE-2026-27904.

Changes

  • Updated eng/common/spelling/package-lock.json to resolve vulnerable minimatch versions.

Target Branch

This PR targets feature/websocket_speech (the branch the Carbon submodule tracks) rather than main to avoid pulling in unrelated feature branch divergence.

@github-actions github-actions bot added Community Contribution Community members are working on the issue customer-reported Issues that are reported by GitHub users external to the Azure organization. labels Apr 9, 2026
@github-actions
Copy link
Copy Markdown

github-actions bot commented Apr 9, 2026

Thank you for your contribution @mohamed-zaki-coding! We will review the pull request and get back to you soon.

@mohamed-zaki-coding mohamed-zaki-coding changed the title Fix CVE-2026-27903/CVE-2026-27904: Upgrade minimatch in spelling package-lock.json Upgrade minimatch in spelling package-lock.json Apr 9, 2026
@mohamed-zaki-coding mohamed-zaki-coding force-pushed the fix/upgrade-minimatch-package branch from 48c5534 to 185a8bf Compare April 9, 2026 18:35
@mohamed-zaki-coding mohamed-zaki-coding force-pushed the fix/upgrade-minimatch-package branch 2 times, most recently from 79565b5 to b33182a Compare April 10, 2026 07:55
Copy link
Copy Markdown
Member

@danieljurek danieljurek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR does get rid of vulnerabilities and passes npm audit but you'll need to get permission here to merge the PR: https://eng.ms/docs/products/azure-developer-experience/onboard/access#request-access-to-azure-rest-api-and-sdk-repositories

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Community Contribution Community members are working on the issue customer-reported Issues that are reported by GitHub users external to the Azure organization.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants