vercel/serve-handler

Vulnerability in minimatch 3.0.4

kachkaev opened this issue ยท 2 comments

Details: https://nvd.nist.gov/vuln/detail/CVE-2022-3517

The version of minimatch is pinned in package.json:

"minimatch": "3.0.4",

Number of weekly package downloads: 2.5M

Screenshot 2022-10-21 at 14 23 36

Could you please merge #180 and release a new version? ๐Ÿ™

Please update minimatch@^3.0.5 ๐Ÿ™