mirror of
http://gh.hjkl01.cn/https://github.com/actions/setup-node
synced 2026-07-30 02:13:15 +08:00
## Basic validation CI fix
Add `overrides` in package.json to eliminate all brace-expansion 1.x and 2.x
from the dependency tree, resolving GHSA-mh99-v99m-4gvg for all packages:
- `"@actions/glob": "$@actions/glob"` - forces @actions/cache to use the
root @actions/glob@0.7.0 (minimatch@10.x → brace-expansion@5.0.8) instead
of its bundled @actions/glob@0.6.1 (minimatch@3.x → brace-expansion@1.x)
- `"glob": {"minimatch": "^10.2.5"}` - forces glob@10.x to use
minimatch@10.x → brace-expansion@5.0.8 instead of minimatch@9.x → brace-expansion@2.x
- `"test-exclude": "^7.0.2"` - upgrades test-exclude to a version that
natively uses minimatch@10.x (instead of @3.x), removing brace-expansion@1.x
from the jest coverage instrumentation path
`npm audit --audit-level=high` now reports 0 vulnerabilities.
## Licensed CI fix
Update .licenses/npm/ cache to match the new dependency tree:
- Add: brace-expansion-5.0.8.dep.yml
- Add: minimatch-10.2.6.dep.yml
- Remove stale: brace-expansion-1.1.13.dep.yml (already done in prev commit)
- Remove stale: brace-expansion-5.0.6.dep.yml (already done in prev commit)
- Remove stale: minimatch-3.1.5.dep.yml
- Remove stale: @actions/glob-0.6.1.dep.yml
- Remove stale: concat-map.dep.yml
- Remove stale: balanced-match-1.0.2.dep.yml
Rebuild dist artifacts to include updated brace-expansion.
67 lines
1.8 KiB
YAML
Generated
67 lines
1.8 KiB
YAML
Generated
---
|
|
name: minimatch
|
|
version: 10.2.6
|
|
type: npm
|
|
summary: a glob matcher in javascript
|
|
homepage:
|
|
license: blueoak-1.0.0
|
|
licenses:
|
|
- sources: LICENSE.md
|
|
text: |
|
|
# Blue Oak Model License
|
|
|
|
Version 1.0.0
|
|
|
|
## Purpose
|
|
|
|
This license gives everyone as much permission to work with
|
|
this software as possible, while protecting contributors
|
|
from liability.
|
|
|
|
## Acceptance
|
|
|
|
In order to receive this license, you must agree to its
|
|
rules. The rules of this license are both obligations
|
|
under that agreement and conditions to your license.
|
|
You must not do anything with this software that triggers
|
|
a rule that you cannot or will not follow.
|
|
|
|
## Copyright
|
|
|
|
Each contributor licenses you to do everything with this
|
|
software that would otherwise infringe that contributor's
|
|
copyright in it.
|
|
|
|
## Notices
|
|
|
|
You must ensure that everyone who gets a copy of
|
|
any part of this software from you, with or without
|
|
changes, also gets the text of this license or a link to
|
|
<https://blueoakcouncil.org/license/1.0.0>.
|
|
|
|
## Excuse
|
|
|
|
If anyone notifies you in writing that you have not
|
|
complied with [Notices](#notices), you can keep your
|
|
license by taking all practical steps to comply within 30
|
|
days after the notice. If you do not do so, your license
|
|
ends immediately.
|
|
|
|
## Patent
|
|
|
|
Each contributor licenses you to do everything with this
|
|
software that would otherwise infringe any patent claims
|
|
they can license or become able to license.
|
|
|
|
## Reliability
|
|
|
|
No contributor can revoke this license.
|
|
|
|
## No Liability
|
|
|
|
**_As far as the law allows, this software comes as is,
|
|
without any warranty or condition, and no contributor
|
|
will be liable to anyone for any damages related to this
|
|
software or this license, under any kind of legal claim._**
|
|
notices: []
|