Skip to content

chore: override eslint-plugin-sonarjs minimatch to clear high alert (#4977) - #4978

Open
NoopDog wants to merge 2 commits into
mainfrom
noopdog/4977-minimatch-override
Open

NoopDog wants to merge 2 commits into
mainfrom
noopdog/4977-minimatch-override

Conversation

@NoopDog

@NoopDog NoopDog commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Closes #4977

What changed

  • package.json: adds an npm override that moves eslint-plugin-sonarjs 3.x onto a patched minimatch:
    "overrides": {
      "eslint-plugin-sonarjs@^3": {
        "minimatch": "^10.2.3"
      }
    }
  • package-lock.json: sonarjs now uses the top-level minimatch@10.2.5 that the rest of the lint tooling already uses. Three entries that nothing else needs are removed: the nested eslint-plugin-sonarjs/node_modules/minimatch@10.1.2, @isaacs/brace-expansion@5.0.1 and @isaacs/balanced-match@4.0.1. Nothing else in the lockfile changes.

Why

Dependabot alert #273 (high, dev-only) flags the root lockfile's minimatch@10.1.2 for three ReDoS advisories, all fixed in 10.2.3:

The only vulnerable copy is the one eslint-plugin-sonarjs pulls in. Its latest 3.x release, 3.0.7, requires exactly minimatch: "10.1.2", so npm audit fix can't fix it without a sonarjs upgrade. That's why #4977's plan of plain npm audit fix didn't work here.

The other parts of #4977 (urllib3 #4957, yaml #4732, picomatch #4730) are already merged, and their alerts are closed.

Assumptions I made

  • Override instead of a major upgrade. I chose this over upgrading eslint-plugin-sonarjs to 4.x. 4.x is a major bump with possible rule changes, and it lands on the same patched minimatch 10.x line, so it adds no security over the override.
  • Override applies only to sonarjs 3.x.
    • Only sonarjs is overridden. A global minimatch override would also force 10.x onto the ten minimatch@3.1.5 copies that eslint, jest and related tools depend on, and break them.
    • The @^3 on the key turns the override off by itself once sonarjs moves to 4.x, whose own minimatch ^10.2.6 needs no override. I checked this by simulating the bump: sonarjs 4.2.2 resolved minimatch@10.2.6 normally. Delete this override in the PR that upgrades sonarjs to 4.x.
  • Floor stays at ^10.2.3, not 4.x's ^10.2.6. 10.2.3 is the first patched version. Raising the floor would only add a second, nested minimatch copy.
  • The rest of npm audit fix is left out. Running it would also bump Next 16.2.9 → 16.4.0, sharp and about 100 other packages. Only minimatch's lockfile entries change here.
  • How the lockfile was regenerated: npm 10.9.2 doesn't re-resolve an entry it has already locked just because an override now excludes it. So I removed the nested 10.1.2 entry and ran npm install --package-lock-only. A fresh lock-only install from the committed state then produces no diff, and npm ci accepts it.
  • Unrelated finding, not fixed here: .github/dependabot.yml points npm version updates at /spa, which doesn't exist, so the root package.json gets no version-update PRs. Security alerts are unaffected.

How to verify

  1. git checkout noopdog/4977-minimatch-override && npm ci. It should finish without modifying package-lock.json (git status stays clean).
  2. npm ls minimatch. eslint-plugin-sonarjs@3.0.7 overridden should sit over minimatch@10.2.5, and no copy should fall in 10.0.0–10.2.2. The 3.1.5 copies are a different major version and aren't affected.
  3. npm audit. minimatch and eslint-plugin-sonarjs should not appear.
  4. npm run lint. It should report 0 errors and the same 42 sonarjs/todo-tag warnings as main. This shows sonarjs still loads and runs with the new minimatch.
  5. npx jest --ci. All 178 tests should pass.
  6. After merge, open Dependabot alert #273. It should show Fixed once Dependabot rescans main.

Definition of done from #4977:

🤖 Generated with Claude Code
🐦 Built with cc-claude-tools

NoopDog and others added 2 commits October 8, 2026 21:39
eslint-plugin-sonarjs 3.0.7, the latest 3.x, pins minimatch to exactly
10.1.2, which is affected by the ReDoS advisories fixed in 10.2.3, so
npm audit fix cannot move it within existing ranges. Override it so
sonarjs dedupes to the hoisted minimatch 10.2.5; the old copy and its
@isaacs/brace-expansion and @isaacs/balanced-match deps drop out of the
lockfile.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Key the override on eslint-plugin-sonarjs@^3 so it stops applying once
sonarjs moves to 4.x, whose own minimatch ^10.2.6 range needs no
override. Without the version scope, the override would silently hold a
4.x sonarjs on minimatch 10.2.5, below what it declares. The lockfile is
unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: cc-claude-tools <cc-claude-tools@clevercanary.com>
@NoopDog NoopDog self-assigned this Oct 9, 2026
@NoopDog
NoopDog requested a balanced review from Copilot October 9, 2026 05:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The scoped override and lockfile cleanup are consistent and preserve unrelated dependency versions.

0 open findings

What changed in this PR

Adds a scoped npm override to resolve the vulnerable minimatch dependency used by SonarJS.

Changes:

  • Overrides SonarJS 3.x to use patched minimatch.
  • Removes obsolete nested lockfile entries.
File Description
package.json Adds the scoped dependency override.
package-lock.json Removes the vulnerable nested dependency tree.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Close the no-code Dependabot batch: urllib3 2.8.0, yaml, picomatch, minimatch

2 participants