Skip to content

fix: update serve-handler to 6.1.7, resolving minimatch 3.1.x security alerts#185

Merged
marc0der merged 1 commit intomainfrom
fix/update-minimatch-and-serialize-js
Mar 3, 2026
Merged

fix: update serve-handler to 6.1.7, resolving minimatch 3.1.x security alerts#185
marc0der merged 1 commit intomainfrom
fix/update-minimatch-and-serialize-js

Conversation

@chloe41427
Copy link
Contributor

@chloe41427 chloe41427 bot commented Mar 3, 2026

Updates serve-handler from 6.1.6 → 6.1.7, which bumps its pinned minimatch dependency from 3.1.2 → 3.1.5.

Resolves Dependabot security alerts:

Change: 7 lines in package-lock.json only. No direct dependencies changed.


⚠️ Note: Alert #53 (serialize-javascript) remains open. It is blocked by @docusaurus/bundler pinning copy-webpack-plugin ^11.0.0, which requires serialize-javascript 6.x. The fix (7.0.3+) requires copy-webpack-plugin v14, a major version bump that Docusaurus has not yet adopted. Needs to be tracked upstream.

@marc0der marc0der merged commit 704250b into main Mar 3, 2026
1 check passed
@marc0der marc0der deleted the fix/update-minimatch-and-serialize-js branch March 3, 2026 20:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant