Skip to content

chore(deps): replace micromatch with picomatch (direct dep) - #69

Merged
IlyaKhD merged 1 commit into
mainfrom
khd/minimatch-picomatch
Oct 7, 2026
Merged

IlyaKhD merged 1 commit into
mainfrom
khd/minimatch-picomatch

Conversation

@IlyaKhD

@IlyaKhD IlyaKhD commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Practical Value

picomatch brings no transitive deps

@IlyaKhD
IlyaKhD requested a balanced review from Copilot October 6, 2026 17:06
@IlyaKhD IlyaKhD self-assigned this Oct 6, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Workspace matching is migrated without tests covering package classification behavior.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Replaces glob-matching dependencies with dependency-free picomatch.

Changes:

  • Migrates path and workspace matching to picomatch.
  • Updates package manifests and lockfile dependencies.
File Description
packages/​common/​src/​path-utils.ts Migrates path matching from minimatch.
packages/​common/​package.json Adds picomatch and its types.
packages/​code-scanning/​src/​validate-lock-files.ts Migrates workspace matching from micromatch.
packages/​code-scanning/​package.json Replaces micromatch dependencies.
pnpm-lock.yaml Updates resolved dependency graph.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread packages/code-scanning/src/validate-lock-files.ts
@IlyaKhD
IlyaKhD merged commit 536c16c into main Oct 7, 2026
1 check passed
@IlyaKhD
IlyaKhD deleted the khd/minimatch-picomatch branch October 7, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants