Skip to content

Change picomatch to 4.0.4#109

Open
ryan-morosa wants to merge 3 commits into
mainfrom
ryanmorosa/bb2-4756-update-picmoatch
Open

Change picomatch to 4.0.4#109
ryan-morosa wants to merge 3 commits into
mainfrom
ryanmorosa/bb2-4756-update-picmoatch

Conversation

@ryan-morosa
Copy link
Copy Markdown
Contributor

@ryan-morosa ryan-morosa commented May 11, 2026

JIRA Ticket:
BB2-4756

What Does This PR Do?

Upgrades picomatch to resolve snyk vulnerability

What Should Reviewers Watch For?

If you're reviewing this PR, please check for these things in particular:

Validation

  • Run npm ls picomatch and yarn list picomatch, confirm you see 4.0.4
  • Run yarn test or npm test, confirm all tests pass. Ensure yarn build or npm build runs successfully, but you may encounter issues with yarn build:types (will be a follow-on story).
    • If having issues with any of these, make sure to remove node_modules and yarn.lock and ensure you have .bluebutton-config.json in src folder.

What Security Implications Does This PR Have?

Please indicate if this PR does any of the following:

  • Adds any new software dependencies
  • Modifies any security controls
  • Adds new transmission or storage of data
  • Any other changes that could possibly affect security?
  • Yes, one or more of the above security implications apply. This PR must not be merged without the ISSO or team security engineer's approval.

@ryan-morosa ryan-morosa changed the title Change picomatch to a higher version Change picomatch to 4.0.4 May 11, 2026
@sb-DarenDean
Copy link
Copy Markdown

Look good to me. Have another engineer look over and approve.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants