Skip to content

Fix npm audit failures on releases/v5 - #1154

Merged
brunoborges merged 3 commits into
actions:releases/v5from
brunoborges:brunoborges-fix-v5-npm-audit
Jul 29, 2026
Merged

Fix npm audit failures on releases/v5#1154
brunoborges merged 3 commits into
actions:releases/v5from
brunoborges:brunoborges-fix-v5-npm-audit

Conversation

@brunoborges

Copy link
Copy Markdown
Contributor

Description:
npm audit --audit-level=high fails on releases/v5 because transitive minimatch, brace-expansion, and js-yaml versions are covered by new denial-of-service advisories.

Override minimatch with the patched 10.2.6 release, refresh the lockfile, and rebuild the checked-in action bundles. The audit now reports zero vulnerabilities.

Related issue:
N/A

Check list:

  • Ran npm run check locally (format, lint, build, test) and all checks pass.
  • Mark if documentation changes are required.
  • Mark if tests were added or updated to cover the changes.

Override minimatch with the patched release and refresh transitive dependencies and bundled action output.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 61439b48-bcf1-4855-94e9-31c4da3e8314
Copilot AI review requested due to automatic review settings July 28, 2026 22:59
@brunoborges
brunoborges requested a review from a team as a code owner July 28, 2026 22:59
@brunoborges
brunoborges changed the base branch from main to releases/v5 July 28, 2026 22:59
@brunoborges brunoborges reopened this Jul 28, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses npm audit --audit-level=high failures on releases/v5 by updating vulnerable transitive dependencies (notably minimatch, brace-expansion, and js-yaml) via an npm override, refreshing the lockfile, and updating the checked-in compiled action bundle output.

Changes:

  • Add an npm overrides entry to force a patched minimatch version.
  • Refresh package-lock.json to resolve updated transitive versions (including brace-expansion and js-yaml).
  • Update the checked-in dist/cleanup/index.js bundle to reflect the new dependency graph.
Show a summary per file
File Description
package.json Adds an npm override to force a patched minimatch version.
package-lock.json Updates resolved transitive dependency versions to eliminate audit findings.
dist/cleanup/index.js Rebuilds the compiled cleanup action bundle with updated dependency contents.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 1/4 changed files
  • Comments generated: 1
  • Review effort level: Low

Comment thread package.json
brunoborges and others added 2 commits July 28, 2026 19:10
Use ESLint's directory and extension arguments so file enumeration does not depend on minimatch handling absolute Windows paths after the security override.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Keep the transitive override at the validated patched release to avoid unrelated changes during future lockfile refreshes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@brunoborges
brunoborges merged commit 6a3384d into actions:releases/v5 Jul 29, 2026
405 checks passed
mergify Bot added a commit to ArcadeData/arcadedb that referenced this pull request Aug 5, 2026
Bumps the github-actions group with 2 updates: [zgosalvez/github-actions-ensure-sha-pinned-actions](https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions) and [actions/setup-java](https://github.com/actions/setup-java).
Updates `zgosalvez/github-actions-ensure-sha-pinned-actions` from 5.0.5 to 5.0.6
Release notes

*Sourced from [zgosalvez/github-actions-ensure-sha-pinned-actions's releases](https://github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/releases).*

> v5.0.6
> ------
>
> What's Changed
> --------------
>
> * Bump eslint from 10.3.0 to 10.8.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#329](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/329)
> * Bump yaml from 2.8.4 to 2.9.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#326](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/326)
> * Bump zgosalvez/github-actions-get-action-runs-using-version from 3.0.1 to 3.0.2 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#324](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/324)
> * Bump stefanzweifel/git-auto-commit-action from 7.1.0 to 7.2.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#323](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/323)
> * Bump actions/checkout from 6.0.3 to 7.0.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#322](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/322)
> * Bump actions/cache from 5.0.5 to 6.1.0 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#321](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/321)
> * Bump `@​vercel/ncc` from 0.38.4 to 0.44.1 by [`@​dependabot`](https://github.com/dependabot)[bot] in [zgosalvez/github-actions-ensure-sha-pinned-actions#325](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/325)
> * Hotfix/dp61 by [`@​zgosalvez`](https://github.com/zgosalvez) in [zgosalvez/github-actions-ensure-sha-pinned-actions#330](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/330)
> * Fix invocations by [`@​zgosalvez`](https://github.com/zgosalvez) in [zgosalvez/github-actions-ensure-sha-pinned-actions#331](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/331)
> * Potential fix for code scanning alert no. 17: Shell command built from environment values by [`@​zgosalvez`](https://github.com/zgosalvez) in [zgosalvez/github-actions-ensure-sha-pinned-actions#332](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/332)
> * Potential fix by [`@​zgosalvez`](https://github.com/zgosalvez) in [zgosalvez/github-actions-ensure-sha-pinned-actions#333](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/333)
> * Another potential fix by [`@​zgosalvez`](https://github.com/zgosalvez) in [zgosalvez/github-actions-ensure-sha-pinned-actions#334](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/pull/334)
>
> **Full Changelog**: <zgosalvez/github-actions-ensure-sha-pinned-actions@v5...v5.0.6>


Commits

* [`46cfe80`](zgosalvez/github-actions-ensure-sha-pinned-actions@46cfe80) Another potential fix ([#334](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/334))
* [`aebb5fc`](zgosalvez/github-actions-ensure-sha-pinned-actions@aebb5fc) Potential fix ([#333](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/333))
* [`2c4885a`](zgosalvez/github-actions-ensure-sha-pinned-actions@2c4885a) Potential fix for code scanning alert no. 17: Shell command built from enviro...
* [`6a25f4a`](zgosalvez/github-actions-ensure-sha-pinned-actions@6a25f4a) Fix invocations ([#331](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/331))
* [`0f97f22`](zgosalvez/github-actions-ensure-sha-pinned-actions@0f97f22) Hotfix/dp61 ([#330](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/330))
* [`1816ffb`](zgosalvez/github-actions-ensure-sha-pinned-actions@1816ffb) Bump `@​vercel/ncc` from 0.38.4 to 0.44.1 ([#325](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/325))
* [`4f14b1e`](zgosalvez/github-actions-ensure-sha-pinned-actions@4f14b1e) Bump actions/cache from 5.0.5 to 6.1.0 ([#321](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/321))
* [`76a5175`](zgosalvez/github-actions-ensure-sha-pinned-actions@76a5175) Bump actions/checkout from 6.0.3 to 7.0.0 ([#322](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/322))
* [`4f0210f`](zgosalvez/github-actions-ensure-sha-pinned-actions@4f0210f) Bump stefanzweifel/git-auto-commit-action from 7.1.0 to 7.2.0 ([#323](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/323))
* [`c616d20`](zgosalvez/github-actions-ensure-sha-pinned-actions@c616d20) Bump zgosalvez/github-actions-get-action-runs-using-version ([#324](https://redirect.github.com/zgosalvez/github-actions-ensure-sha-pinned-actions/issues/324))
* Additional commits viewable in [compare view](zgosalvez/github-actions-ensure-sha-pinned-actions@3db98c0...46cfe80)
  
Updates `actions/setup-java` from 5.6.0 to 5.7.0
Release notes

*Sourced from [actions/setup-java's releases](https://github.com/actions/setup-java/releases).*

> v5.7.0
> ------
>
> What's Changed
> --------------
>
> * Fix npm audit failures on releases/v5 by [`@​brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1154](https://redirect.github.com/actions/setup-java/pull/1154)
> * Backport [#1151](https://redirect.github.com/actions/setup-java/issues/1151): Fix missing wrapper cache distributions by [`@​brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1153](https://redirect.github.com/actions/setup-java/pull/1153)
> * Deprecate legacy Adopt distributions in v5 by [`@​brunoborges`](https://github.com/brunoborges) in [actions/setup-java#1186](https://redirect.github.com/actions/setup-java/pull/1186)
>
> **Full Changelog**: <actions/setup-java@v5.6.0...v5.7.0>


Commits

* [`b6effb0`](actions/setup-java@b6effb0) Deprecate legacy Adopt distributions in v5 ([#1186](https://redirect.github.com/actions/setup-java/issues/1186))
* [`e498d2a`](actions/setup-java@e498d2a) Backport [#1151](https://redirect.github.com/actions/setup-java/issues/1151): Fix missing wrapper cache distributions ([#1153](https://redirect.github.com/actions/setup-java/issues/1153))
* [`6a3384d`](actions/setup-java@6a3384d) Fix npm audit failures on releases/v5 ([#1154](https://redirect.github.com/actions/setup-java/issues/1154))
* See full diff in [compare view](actions/setup-java@03ad4de...b6effb0)
  
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
  
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show  ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore  major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore  minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore  ` will remove the ignore condition of the specified dependency and ignore conditions
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants