Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-20 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-19 | 0 | 0 | 0 | 0 | 7 |
| 2026-09-18 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-17 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-16 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-15 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-14 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-13 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-12 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-11 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-10 | 1 | 0 | 0 | 0 | 0 |
| 2026-09-09 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-07 | 0 | 0 | 0 | 0 | 0 |
Opened: 0
Closed: 0
Comments: 0
Events: 0
No label distribution is available yet.
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#323 Package no longer installable on Node 18 Opened 11 days ago | tstarling | open | No labels | 1 | 0 | 10 days ago |
#318 optimizationLevel 2 lets .. erase the Windows drive root and UNC share from patterns Opened 29 days ago | chuanghiduoc | open | No labels | 0 | 0 | 29 days ago |
#314 Vulnerability of brace-expansion in 3.1.5 v of minimatch Opened 2 months ago | AdityaAtBentley | closed - completed | No labels | 4 | 3 | 2 months ago |
#302 Security issue in dependency [email protected] Opened 4 months ago | michix | closed - completed | No labels | 4 | 7 | 2 months ago |
#312 Security: update brace-expansion to 5.0.7 Opened 2 months ago | yassinedorbozgithub | closed - completed | No labels | 1 | 2 | 2 months ago |
#313 Security Advisory GHSA-mh99-v99m-4gvg: ReDoS vulnerability in minimatch Opened 2 months ago | paul1k | closed - completed | No labels | 0 | 0 | 2 months ago |
#311 Node support policy Opened 2 months ago | nxmndr | closed - completed | No labels | 3 | 0 | 2 months ago |
#310 Security issue in brace-expansion dependency for earlier versions of minimatch Opened 3 months ago | zsharpBDO | closed - completed | No labels | 1 | 0 | 2 months ago |
#307 Staged Publishing — 654M weekly downloads behind one npm token Opened 3 months ago | piiiico | closed - completed | No labels | 1 | 0 | 3 months ago |
#298 GHSA-23c5-xmqv-rm74: claimed fixed versions 8.0.6 and 6.2.2 ship pre-fix compiled output (build pipeline not run) Opened 5 months ago | DEVSOG12 | closed - completed | No labels | 2 | 0 | 5 months ago |
#297 Engines in package.json Opened 5 months ago | shaunaas | closed - completed | No labels | 1 | 0 | 5 months ago |
#296 Request: backport ReDoS fix to 3.x line (CVE-2026-27903, CVE-2026-27904, CVE-2026-26996) Opened 6 months ago | vasiliiperfilev | closed - completed | No labels | 1 | 6 | 5 months ago |
#295 [v3] Update dependency to fix vulnerability Opened 6 months ago | gmanole01 | closed - completed | No labels | 1 | 0 | 6 months ago |
#274 a slash can break the extglob syntax Opened 8 months ago | hgl | open | No labels | 3 | 0 | 6 months ago |
#219 Feature Request: Testing against multiple patterns Opened 3 years ago | matwilko | open | No labels | 2 | 2 | 6 months ago |
#226 Support GLOBSTARSHORT Opened 3 years ago | danielbayley | open | No labels | 1 | 0 | 6 months ago |
#246 How to match exact start of string? Opened 2 years ago | az-nextsec | open | No labels | 0 | 0 | 6 months ago |
#273 Invalid regex generated when glob includes comma and character class Opened 11 months ago | pkaminski | open | No labels | 0 | 0 | 6 months ago |
#291 Any plan to backport CVE-2026-26996 fix to 9.x for Node 18 users? Opened 7 months ago | Yuchen-Dai | closed - completed | No labels | 2 | 0 | 7 months ago |
#290 National Vulnerability Database is not updated for CVE-2026-26996 Opened 7 months ago | AkosSz | closed - completed | No labels | 1 | 0 | 7 months ago |
#282 Possible regression in v9 with new versions Opened 7 months ago | G-Rath | closed - completed | No labels | 4 | 1 | 7 months ago |
#286 versions >= 9.0.6 is a breaking change Opened 7 months ago | zhonig | closed - completed | No labels | 11 | 0 | 7 months ago |
#287 CVE-2026-26996 - Resolved for version 3.1.3, but vulnerable to 3.1.4 ? Opened 7 months ago | Raazor | closed - completed | No labels | 1 | 0 | 7 months ago |
#284 [3.1.4/4.2.5/5.1.8/6.2.2/7.4.8/8.0.6/9.0.7/10.2.3 regression] `minimatch("a", "a/**", { partial: true })` incorrectly returns `false` Opened 7 months ago | andersk | closed - completed | No labels | 6 | 13 | 7 months ago |
#285 Matching change in v3.1.4 Opened 7 months ago | bmarker | closed - duplicate | No labels | 1 | 1 | 7 months ago |