Bump NPM dependencies to resolve dependabot security alerts #236

Closed
opened 2026-04-05 16:23:20 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @jnovinger on 3/4/2026

Proposed Changes

Bump the following NPM dependencies in netbox/project-static/ per open dependabot alerts:

  • minimatch 3.1.2 → 3.1.3 (transitive dep via eslint, eslint-plugin-import)
  • markdown-it 14.1.0 → 14.1.1 (transitive dep via netbox-graphiql → graphiql → @graphiql/react)

Justification

Two open dependabot security alerts:

  • minimatch (GHSA-7r86-cg39-jmmj) — High severity ReDoS via combinatorial backtracking in matchOne() with multiple non-adjacent GLOBSTAR segments
  • markdown-it (CVE-2026-2327) — Medium severity ReDoS

Both are patch-level bumps in transitive dependencies, resolved by updating yarn.lock.

*Originally created by @jnovinger on 3/4/2026* ### Proposed Changes Bump the following NPM dependencies in `netbox/project-static/` per open dependabot alerts: - `minimatch` 3.1.2 → 3.1.3 (transitive dep via eslint, eslint-plugin-import) - `markdown-it` 14.1.0 → 14.1.1 (transitive dep via netbox-graphiql → graphiql → @graphiql/react) ### Justification Two open dependabot security alerts: - **minimatch** ([GHSA-7r86-cg39-jmmj](https://github.com/isaacs/minimatch/security/advisories/GHSA-7r86-cg39-jmmj)) — High severity ReDoS via combinatorial backtracking in `matchOne()` with multiple non-adjacent GLOBSTAR segments - **markdown-it** ([CVE-2026-2327](https://nvd.nist.gov/vuln/detail/CVE-2026-2327)) — Medium severity ReDoS Both are patch-level bumps in transitive dependencies, resolved by updating `yarn.lock`.
Sign in to join this conversation.
No Label netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox netbox status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted status: accepted type: housekeeping type: housekeeping type: housekeeping type: housekeeping type: housekeeping type: housekeeping type: housekeeping type: housekeeping
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/netbox#236