Skip to content

Commit 55212af

Browse files
committed
Fix ESLint failure on Windows due to minimatch v10 override and add lint to CI
The minimatch override in package.json used >=3.1.2 (unbounded) to address a ReDoS vulnerability, which allowed npm to resolve minimatch to v10.x. Minimatch v10 changed backslash handling: backslashes are now treated as escape characters by default, not path separators. ESLint v8's FileEnumerator calls path.resolve() on glob patterns, producing Windows paths like C:\...\lib\src\**\*.ts, then passes them to minimatch without the windowsPathsNoEscape option. This causes glob matching to silently fail — no .ts files are found — and grunt dynamicproto errors out with 'No files matching ./lib/src/**/*.ts were found.' Fix: constrain the override to ~3.1.2 (3.1.x only, currently 3.1.5). The ReDoS security fix is included, and backslashes still work as path separators, which is what ESLint v8 expects. Also adds an explicit 'npm run lint' step to the CI workflow so ESLint failures are caught in PR builds before the build step.
1 parent 6d5b984 commit 55212af

2 files changed

Lines changed: 2 additions & 1 deletion

File tree

‎.github/workflows/ci.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,7 @@ jobs:
2525
with:
2626
node-version: ${{ matrix.node-version }}
2727
- run: npm install
28+
- run: npm run lint
2829
- run: npm run build --verbose
2930
timeout-minutes: 10
3031
- run: npm run test --verbose

‎package.json‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@
4444
},
4545
"homepage": "https://github.com/microsoft/DynamicProto-JS#readme",
4646
"overrides": {
47-
"minimatch": ">=3.1.2"
47+
"minimatch": "~3.1.2"
4848
},
4949
"dependencies": {
5050
"@nevware21/ts-utils": ">= 0.14.0 < 2.x"

0 commit comments

Comments
 (0)