Skip to content

Conversation

@zachstence
Copy link
Contributor

@zachstence zachstence commented Dec 9, 2025

Update rimraf to 6.1.2 (latest) to resolve security vulnerability in glob

GHSA-5j98-mcp5-4vw2

This is affecting @posthog/cli

All of the snapshot updates are in npm-shrinkwrap.json and are due to me updating rimraf via npm i rimraf@latest. I assume they are okay, but I don't have enough familiarity with the project to know for certain.

@mistydemeo
Copy link
Contributor

Thanks for taking care of this. I'll try to get a release out with this update soon.

@mistydemeo
Copy link
Contributor

Looks like one of the snapshots didn't update properly. I can handle this in the dependabot PR if you'd like.

@zachstence
Copy link
Contributor Author

Sure, feel free to handle it in the dependabot PR or here (allow edits by maintainers is turned on!).

Thanks for getting this across the line!

@mistydemeo
Copy link
Contributor

Thanks! I'll get a point release out tonight.

@mistydemeo mistydemeo merged commit 939962d into axodotdev:main Dec 12, 2025
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants