Skip to content

Conversation

@baranbbr
Copy link

@baranbbr baranbbr commented Nov 27, 2025

Caution

This should NOT be merged to master.

PR Checklist

Please check if your PR fulfills the following requirements:

PR Type

What kind of change does this PR introduce?

[ ] Bugfix
[ ] Feature
[ ] Code style update (formatting, local variables)
[x] Refactoring (no functional changes, no api changes)
[ ] Build related changes
[ ] CI related changes
[ ] Other... Please describe:

What is the current behavior?

Updating glob package in old release 10.
This is to address CVE-2025-64756
https://security.snyk.io/vuln/SNYK-JS-GLOB-14040952

Related to Issue Number: #3189

What is the new behavior?

Does this PR introduce a breaking change?

[ ] Yes
[x] No

Other information

@baranbbr baranbbr changed the title fix(deps): update vulnerable glob pkg to 10.5.0 fix(deps): update vulnerable glob pkg to 10.5.0 in v10.x Nov 27, 2025
@baranbbr
Copy link
Author

baranbbr commented Nov 27, 2025

This is a backport for version 10.x - looking at the recent releases it looks like older versions aren't updated? I'm not sure how the maintainers want to proceed? Imo there's value in creating a maintenance branch/release on version 10.

Version 10.4.9 is still massively popular as I can see on npm: https://www.npmjs.com/package/@nestjs/cli?activeTab=versions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant