Package
kibana-9.0-iamguarded
Component
minimatch
Latest update
Fixed version
9.0.8-r13
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
9.0.8-r13Status
Impact
GHSA-3ppc-4f35-3m26 affects minimatch at multiple nested locations in the dependency tree (direct dep, transitive via glob@^3.0.4, and transitive via readdir-glob). Attempts to bump via yarn upgrade shift the vulnerable instance to a different location rather than eliminating it, as each package has a separate lock entry with different version constraints. Fix requires upstream to update the full dependency tree in a coordinated release.
Status