An open index of dependabot pull requests across open source projects.

Bump picomatch from 2.3.1 to 2.3.2

Open
Number: #430
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Unknown
Comments: 1
Created: March 26, 2026 at 12:14 AM UTC
(3 months ago)
Updated: May 10, 2026 at 10:58 AM UTC
(about 1 month ago)
Labels:
dependencies javascript size/XS
Description:

Bumps picomatch from 2.3.1 to 2.3.2.

Release notes

Sourced from picomatch's releases.

2.3.2

This is a security release fixing several security relevant issues.

What's Changed

Full Changelog: https://github.com/micromatch/picomatch/compare/2.3.1...2.3.2

Changelog

Sourced from picomatch's changelog.

Release history

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog and this project adheres to Semantic Versioning.

  • Changelogs are for humans, not machines.
  • There should be an entry for every single version.
  • The same types of changes should be grouped.
  • Versions and sections should be linkable.
  • The latest version comes first.
  • The release date of each versions is displayed.
  • Mention whether you follow Semantic Versioning.

Changelog entries are classified using the following labels (from keep-a-changelog):

  • Added for new features.
  • Changed for changes in existing functionality.
  • Deprecated for soon-to-be removed features.
  • Removed for now removed features.
  • Fixed for any bug fixes.
  • Security in case of vulnerabilities.

4.0.0 (2024-02-07)

Fixes

Changed

3.0.1

Fixes

... (truncated)

Commits

Package Dependencies
Package:
picomatch
Ecosystem:
npm
Version Change:
2.3.1 → 2.3.2
Update Type:
Patch
Technical Details
ID: 15731965
UUID: 4139423584
Node ID: PR_kwDOEv2Gq87Nh5JE
Host: GitHub
Repository: Wayfapper/UserScript