Skip to content

chore(deps): bump picomatch from 4.0.3 to 4.0.4#23

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/picomatch-4.0.4
Open

chore(deps): bump picomatch from 4.0.3 to 4.0.4#23
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/picomatch-4.0.4

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot bot commented on behalf of github Mar 26, 2026

Bumps picomatch from 4.0.3 to 4.0.4.

Release notes

Sourced from picomatch's releases.

4.0.4

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: micromatch/picomatch@4.0.3...4.0.4

Commits

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Mar 26, 2026
Copy link
Copy Markdown

@doistbot-app doistbot-app bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This update bumps the picomatch development dependency to version 4.0.4, addressing recent security vulnerabilities. It's a straightforward maintenance bump that helps keep our project secure, and no issues were flagged during the review.

Share FeedbackReview Logs

Bumps [picomatch](https://github.com/micromatch/picomatch) from 4.0.3 to 4.0.4.
- [Release notes](https://github.com/micromatch/picomatch/releases)
- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGELOG.md)
- [Commits](micromatch/picomatch@4.0.3...4.0.4)

---
updated-dependencies:
- dependency-name: picomatch
  dependency-version: 4.0.4
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the title chore(deps-dev): bump picomatch from 4.0.3 to 4.0.4 chore(deps): bump picomatch from 4.0.3 to 4.0.4 Apr 2, 2026
@dependabot dependabot bot force-pushed the dependabot/npm_and_yarn/picomatch-4.0.4 branch from 48d5364 to 16cccd0 Compare April 2, 2026 14:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants