Extension Parameter Validator 0.3.2, released 2026-04-02
April 2, 2026 ยท View on GitHub
Code name: Fix dependabot alerts in vulnerable dependencies
Summary
This release migrates the release process to trusted publishing. This improves security of the release process by avoiding tokens. The release also fixes the following dependabot alerts:
- #33: Prototype Pollution via parse() in NodeJS flatted
- #30: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- #28: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- #27: minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
- #34: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
- #16: js-yaml has prototype pollution in merge (<<)
- #15: js-yaml has prototype pollution in merge (<<)
Security
- #16: Fix dependabot alerts
Dependency Updates
Compile Dependency Updates
- Updated
@exasol/extension-manager-interface:0.4.3to0.5.1
Development Dependency Updates
- Updated
eslint:9.20.0to^10.1.0 - Added
@eslint/js:^10.0.1 - Updated
@types/node:^22.13.1to^25.5.0 - Updated
ts-jest:^29.2.5to^29.4.6 - Updated
@types/jest:^29.5.14to^30.0.0 - Updated
typescript-eslint:^8.23.0to^8.58.0 - Updated
typescript:5.7.3to^5.9.3 - Updated
jest:^29.7.0to^30.3.0