-
-
Notifications
You must be signed in to change notification settings - Fork 6.6k
chore: update to glob v12 #15894
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore: update to glob v12 #15894
Conversation
✅ Deploy Preview for jestjs ready!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
babel-jest
babel-plugin-jest-hoist
babel-preset-jest
create-jest
@jest/diff-sequences
expect
@jest/expect-utils
jest
jest-changed-files
jest-circus
jest-cli
jest-config
@jest/console
@jest/core
@jest/create-cache-key-function
jest-diff
jest-docblock
jest-each
@jest/environment
jest-environment-jsdom
@jest/environment-jsdom-abstract
jest-environment-node
@jest/expect
@jest/fake-timers
@jest/get-type
@jest/globals
jest-haste-map
jest-jasmine2
jest-leak-detector
jest-matcher-utils
jest-message-util
jest-mock
@jest/pattern
jest-phabricator
jest-regex-util
@jest/reporters
jest-resolve
jest-resolve-dependencies
jest-runner
jest-runtime
@jest/schemas
jest-snapshot
@jest/snapshot-utils
@jest/source-map
@jest/test-result
@jest/test-sequencer
@jest/transform
@jest/types
jest-util
jest-validate
jest-watcher
jest-worker
pretty-format
commit: |
|
Glob 11.1.0 should be patched. Maybe that still has support for node 18. |
|
@BenjaminBLarsen the fix is only in glob |
|
glob 10.5 was released 9 hours ago, so this is not needed. https://github.com/isaacs/node-glob/commits/v10/ thanks for the PR, tho! |
Summary
This PR updates
globto v12.0.0 to fix #15892 and the CVE behind it (GHSA-5j98-mcp5-4vw2).This CVE is marked as high and should be fixed immediately. Sadly glob v11 dropped support for node < 20 and jest still supports 18. I guess this means the support for 18 has to be dropped and this will then be a major release? Please let me know what you think about this.
Test plan
Green CI