- Notifications
You must be signed in to change notification settings - Fork421
fix(deps): update vulnerable glob pkg to10.5.0 in v10.x#3199
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
base:master
Are you sure you want to change the base?
Uh oh!
There was an error while loading.Please reload this page.
Conversation
10.5.0 in v10.xbaranbbr commentedNov 27, 2025 • edited
Loading Uh oh!
There was an error while loading.Please reload this page.
edited
Uh oh!
There was an error while loading.Please reload this page.
This is a backport for version Version |
baranbbr commentedDec 2, 2025
@kamilmysliwiec I guess there are no plans to maintain previous major versions? If so, feel free to close this |
ooxx5626 commentedDec 3, 2025
We are also using version 10.x and would like to receive a remediated/patched version 10.X to address this CVE. |
arketec commentedDec 8, 2025
in the meantime, you can override glob on this dependency only in your package.json npm yarn: |
Uh oh!
There was an error while loading.Please reload this page.
Caution
This shouldNOT be merged to master.
PR Checklist
Please check if your PR fulfills the following requirements:
PR Type
What kind of change does this PR introduce?
What is the current behavior?
Updating glob package in old release 10.
This is to address
CVE-2025-64756https://security.snyk.io/vuln/SNYK-JS-GLOB-14040952
Related to Issue Number:#3189
What is the new behavior?
Does this PR introduce a breaking change?
Other information