Repository navigation
Conversation
eslint-plugin-sonarjs 3.0.7, the latest 3.x, pins minimatch to exactly 10.1.2, which is affected by the ReDoS advisories fixed in 10.2.3, so npm audit fix cannot move it within existing ranges. Override it so sonarjs dedupes to the hoisted minimatch 10.2.5; the old copy and its @isaacs/brace-expansion and @isaacs/balanced-match deps drop out of the lockfile. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Key the override on eslint-plugin-sonarjs@^3 so it stops applying once sonarjs moves to 4.x, whose own minimatch ^10.2.6 range needs no override. Without the version scope, the override would silently hold a 4.x sonarjs on minimatch 10.2.5, below what it declares. The lockfile is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: cc-claude-tools <cc-claude-tools@clevercanary.com>
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The scoped override and lockfile cleanup are consistent and preserve unrelated dependency versions.
0 open findings
What changed in this PR
Adds a scoped npm override to resolve the vulnerable minimatch dependency used by SonarJS.
Changes:
- Overrides SonarJS 3.x to use patched
minimatch. - Removes obsolete nested lockfile entries.
| File | Description |
|---|---|
package.json |
Adds the scoped dependency override. |
package-lock.json |
Removes the vulnerable nested dependency tree. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
2 tasks
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #4977
What changed
package.json: adds an npm override that moveseslint-plugin-sonarjs3.x onto a patched minimatch:package-lock.json: sonarjs now uses the top-levelminimatch@10.2.5that the rest of the lint tooling already uses. Three entries that nothing else needs are removed: the nestedeslint-plugin-sonarjs/node_modules/minimatch@10.1.2,@isaacs/brace-expansion@5.0.1and@isaacs/balanced-match@4.0.1. Nothing else in the lockfile changes.Why
Dependabot alert #273 (high, dev-only) flags the root lockfile's
minimatch@10.1.2for three ReDoS advisories, all fixed in 10.2.3:The only vulnerable copy is the one
eslint-plugin-sonarjspulls in. Its latest 3.x release, 3.0.7, requires exactlyminimatch: "10.1.2", sonpm audit fixcan't fix it without a sonarjs upgrade. That's why #4977's plan of plainnpm audit fixdidn't work here.The other parts of #4977 (urllib3 #4957, yaml #4732, picomatch #4730) are already merged, and their alerts are closed.
Assumptions I made
eslint-plugin-sonarjsto 4.x. 4.x is a major bump with possible rule changes, and it lands on the same patched minimatch 10.x line, so it adds no security over the override.minimatchoverride would also force 10.x onto the tenminimatch@3.1.5copies that eslint, jest and related tools depend on, and break them.@^3on the key turns the override off by itself once sonarjs moves to 4.x, whose ownminimatch ^10.2.6needs no override. I checked this by simulating the bump: sonarjs 4.2.2 resolvedminimatch@10.2.6normally. Delete this override in the PR that upgrades sonarjs to 4.x.^10.2.3, not 4.x's^10.2.6. 10.2.3 is the first patched version. Raising the floor would only add a second, nested minimatch copy.npm audit fixis left out. Running it would also bump Next 16.2.9 → 16.4.0, sharp and about 100 other packages. Only minimatch's lockfile entries change here.npm install --package-lock-only. A fresh lock-only install from the committed state then produces no diff, andnpm ciaccepts it..github/dependabot.ymlpoints npm version updates at/spa, which doesn't exist, so the rootpackage.jsongets no version-update PRs. Security alerts are unaffected.How to verify
git checkout noopdog/4977-minimatch-override && npm ci. It should finish without modifyingpackage-lock.json(git statusstays clean).npm ls minimatch.eslint-plugin-sonarjs@3.0.7 overriddenshould sit overminimatch@10.2.5, and no copy should fall in 10.0.0–10.2.2. The3.1.5copies are a different major version and aren't affected.npm audit. minimatch and eslint-plugin-sonarjs should not appear.npm run lint. It should report 0 errors and the same 42sonarjs/todo-tagwarnings asmain. This shows sonarjs still loads and runs with the new minimatch.npx jest --ci. All 178 tests should pass.main.Definition of done from #4977:
mainand CI passes. urllib3, yaml and picomatch are already merged. minimatch lands with this PR (steps 1–5, and this PR's CI).requirements.txtclosed on rescan, with no dismissal needed. minimatch Split "Disease" facets into two levels #273 closes after merge (step 6).🤖 Generated with Claude Code
🐦 Built with cc-claude-tools