Skip to content

Commit 7256d9e

Browse files
authored
feat(deps): Bump glob in @sentry/react-router (#19162)
Bumps `glob` from `11.1.0` to `13.0.1` in `@sentry/react-router` to resolve a security vulnerability in the transitive dependency `@isaacs/brace-expansion`. Dependency chain: `@sentry/react-router` → `glob` → `minimatch` → `@isaacs/brace-expansion` Details The previous version of `glob` (11.1.0) pulled in a vulnerable version of `@isaacs/brace-expansion`. The vulnerability has been patched upstream: `@isaacs/brace-expansion` was patched `minimatch` released a new version with the fix `glob` 13.0.1 includes the updated dependencies This is a dependency-only change with no code modifications. [CVE](GHSA-7h2j-956f-4vf2)
1 parent 602f42d commit 7256d9e

2 files changed

Lines changed: 13 additions & 32 deletions

File tree

packages/react-router/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
"@sentry/node": "10.38.0",
5656
"@sentry/react": "10.38.0",
5757
"@sentry/vite-plugin": "^4.8.0",
58-
"glob": "11.1.0"
58+
"glob": "^13.0.1"
5959
},
6060
"devDependencies": {
6161
"@react-router/dev": "^7.13.0",

yarn.lock

Lines changed: 12 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -5385,7 +5385,7 @@
53855385
resolved "https://registry.yarnpkg.com/@isaacs/balanced-match/-/balanced-match-4.0.1.tgz#3081dadbc3460661b751e7591d7faea5df39dd29"
53865386
integrity sha512-yzMTt9lEb8Gv7zRioUilSglI0c0smZ9k5D65677DLWLtWJaXIS3CqcGyUFByYKlnUj6TkjLVs54fBl6+TiGQDQ==
53875387

5388-
"@isaacs/brace-expansion@^5.0.0":
5388+
"@isaacs/brace-expansion@^5.0.1":
53895389
version "5.0.1"
53905390
resolved "https://registry.yarnpkg.com/@isaacs/brace-expansion/-/brace-expansion-5.0.1.tgz#0ef5a92d91f2fff2a37646ce54da9e5f599f6eff"
53915391
integrity sha512-WMz71T1JS624nWj2n2fnYAuPovhv7EUhk69R6i9dsVyzxt5eM3bjwvgk9L+APE1TRscGysAVMANkB0jh0LQZrQ==
@@ -18526,7 +18526,7 @@ for-in@^1.0.2:
1852618526
resolved "https://registry.yarnpkg.com/for-in/-/for-in-1.0.2.tgz#81068d295a8142ec0ac726c6e2200c30fb6d5e80"
1852718527
integrity sha1-gQaNKVqBQuwKxybG4iAMMPttXoA=
1852818528

18529-
foreground-child@^3.1.0, foreground-child@^3.3.1:
18529+
foreground-child@^3.1.0:
1853018530
version "3.3.1"
1853118531
resolved "https://registry.yarnpkg.com/foreground-child/-/foreground-child-3.3.1.tgz#32e8e9ed1b68a3497befb9ac2b6adf92a638576f"
1853218532
integrity sha512-gIXjKqtFuWEgzFRJA9WCQeSJLZDjgJUOMCMzxtvFq/37KojM1BFGufqsCy0r4qSQmYLsZYMeyRqzIWOMup03sw==
@@ -19096,18 +19096,6 @@ glob-to-regexp@^0.4.1:
1909619096
resolved "https://registry.yarnpkg.com/glob-to-regexp/-/glob-to-regexp-0.4.1.tgz#c75297087c851b9a578bd217dd59a92f59fe546e"
1909719097
integrity sha512-lkX1HJXwyMcprw/5YUZc2s7DrpAiHB21/V+E1rHUrVNokkvB6bqMzT0VfV6/86ZNabt1k14YOIaT7nDvOX3Iiw==
1909819098

19099-
glob@11.1.0:
19100-
version "11.1.0"
19101-
resolved "https://registry.yarnpkg.com/glob/-/glob-11.1.0.tgz#4f826576e4eb99c7dad383793d2f9f08f67e50a6"
19102-
integrity sha512-vuNwKSaKiqm7g0THUBu2x7ckSs3XJLXE+2ssL7/MfTGPLLcrJQ/4Uq1CjPTtO5cCIiRxqvN6Twy1qOwhL0Xjcw==
19103-
dependencies:
19104-
foreground-child "^3.3.1"
19105-
jackspeak "^4.1.1"
19106-
minimatch "^10.1.1"
19107-
minipass "^7.1.2"
19108-
package-json-from-dist "^1.0.0"
19109-
path-scurry "^2.0.0"
19110-
1911119099
glob@8.0.3:
1911219100
version "8.0.3"
1911319101
resolved "https://registry.yarnpkg.com/glob/-/glob-8.0.3.tgz#415c6eb2deed9e502c68fa44a272e6da6eeca42e"
@@ -19131,12 +19119,12 @@ glob@^10.0.0, glob@^10.2.2, glob@^10.3.10, glob@^10.3.4, glob@^10.3.7, glob@^10.
1913119119
package-json-from-dist "^1.0.0"
1913219120
path-scurry "^1.11.1"
1913319121

19134-
glob@^13.0.0:
19135-
version "13.0.0"
19136-
resolved "https://registry.yarnpkg.com/glob/-/glob-13.0.0.tgz#9d9233a4a274fc28ef7adce5508b7ef6237a1be3"
19137-
integrity sha512-tvZgpqk6fz4BaNZ66ZsRaZnbHvP/jG3uKJvAZOwEVUL4RTA5nJeeLYfyN9/VA8NX/V3IBG+hkeuGpKjvELkVhA==
19122+
glob@^13.0.0, glob@^13.0.1:
19123+
version "13.0.1"
19124+
resolved "https://registry.yarnpkg.com/glob/-/glob-13.0.1.tgz#c59a2500c9a5f1ab9cdd370217ced63c2aa81e60"
19125+
integrity sha512-B7U/vJpE3DkJ5WXTgTpTRN63uV42DseiXXKMwG14LQBXmsdeIoHAPbU/MEo6II0k5ED74uc2ZGTC6MwHFQhF6w==
1913819126
dependencies:
19139-
minimatch "^10.1.1"
19127+
minimatch "^10.1.2"
1914019128
minipass "^7.1.2"
1914119129
path-scurry "^2.0.0"
1914219130

@@ -21190,13 +21178,6 @@ jackspeak@^3.1.2:
2119021178
optionalDependencies:
2119121179
"@pkgjs/parseargs" "^0.11.0"
2119221180

21193-
jackspeak@^4.1.1:
21194-
version "4.1.1"
21195-
resolved "https://registry.yarnpkg.com/jackspeak/-/jackspeak-4.1.1.tgz#96876030f450502047fc7e8c7fcf8ce8124e43ae"
21196-
integrity sha512-zptv57P3GpL+O0I7VdMJNBZCu+BPHVQUk55Ft8/QCJjTVxrnJHuVuX/0Bl2A6/+2oyR/ZMEuFKwmzqqZ/U5nPQ==
21197-
dependencies:
21198-
"@isaacs/cliui" "^8.0.2"
21199-
2120021181
jake@^10.8.5:
2120121182
version "10.8.5"
2120221183
resolved "https://registry.yarnpkg.com/jake/-/jake-10.8.5.tgz#f2183d2c59382cb274226034543b9c03b8164c46"
@@ -23444,12 +23425,12 @@ minimatch@9.0.3:
2344423425
dependencies:
2344523426
brace-expansion "^2.0.1"
2344623427

23447-
minimatch@^10.1.1:
23448-
version "10.1.1"
23449-
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-10.1.1.tgz#e6e61b9b0c1dcab116b5a7d1458e8b6ae9e73a55"
23450-
integrity sha512-enIvLvRAFZYXJzkCYG5RKmPfrFArdLv+R+lbQ53BmIMLIry74bjKzX6iHAm8WYamJkhSSEabrWN5D97XnKObjQ==
23428+
minimatch@^10.1.2:
23429+
version "10.1.2"
23430+
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-10.1.2.tgz#6c3f289f9de66d628fa3feb1842804396a43d81c"
23431+
integrity sha512-fu656aJ0n2kcXwsnwnv9g24tkU5uSmOlTjd6WyyaKm2Z+h1qmY6bAjrcaIxF/BslFqbZ8UBtbJi7KgQOZD2PTw==
2345123432
dependencies:
23452-
"@isaacs/brace-expansion" "^5.0.0"
23433+
"@isaacs/brace-expansion" "^5.0.1"
2345323434

2345423435
minimatch@^7.4.1:
2345523436
version "7.4.6"

0 commit comments

Comments
 (0)