Skip to content

[Snyk - High] fecfile-validate: update vulnerable dependency chains (ajv, glob, minimatch, eslint) (03/22/2026) #411

@exalate-issue-sync

Description

@exalate-issue-sync

Snyk warning: https://app.snyk.io/org/fecfile/project/377bba3f-d9ef-402b-a5b5-a4ac5934a0d4

current state after dependency updates and audit cleanup is the expected residual state.

commands run:

npm audit --omit=dev
npm ls fecfile-validate ajv glob minimatch --all

result: 4 vulnerabilities remain, all from the fecfile-validate transitive dependency chain

affected chain:

Success Criteria

npm audit --omit=dev no longer reports vulnerabilities from the fecfile-validate chain (ajv / glob / minimatch).

QA Notes

null

DEV Notes

null

Design

null

See full ticket and images here: FECFILE-2884

Pull Request: #412

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions