- Regenerated package-lock.json to pick up brace-expansion@5.0.9 (fixes
GHSA-rgw5-rvv9-x895, a DoS via unbounded intermediate arrays), which
is already permitted by minimatch's existing ^5.0.8 semver range.
- Refreshed .licenses/npm cache to match the updated dependency tree.
- Added minimatch to the licensed.yml reviewed list: its detected
license text doesn't cleanly match Blue Oak 1.0.0, which is already
in the allowed list.
- Rebuilt dist/setup and dist/cache-save from source.
npm audit --audit-level=high now reports 0 vulnerabilities;
licensed status reports 0 errors; npm run pre-checkin passes locally.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* Migrate to ESM and upgrade dependencies
* Remove unused tsconfig.eslint.json
* bump version to 7.0.0 in package.json and package-lock.json
* Add ESM migration note to README for V7
* Remove unnecessary devDependencies: ts-node, @types/jest
* npm audit fix
* Update README with ESM migration details
Clarified migration details to ESM for action compatibility.
* Downgrade @types/node to ^24, clean up tsconfig and README.