Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jul 9, 2024

Coming soon: The Renovate bot (GitHub App) will be renamed to Mend. PRs from Renovate will soon appear from 'Mend'. Learn more here.

This PR contains the following updates:

Package Change Age Confidence
glob ^10.0.0 -> ^11.0.0 age confidence

Release Notes

isaacs/node-glob (glob)

v11.0.3

Compare Source

v11.0.2

Compare Source

v11.0.1

Compare Source

v11.0.0

Compare Source


Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM ( * 0-3 * * * ) in timezone America/Chicago, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Upgrade or downgrade of project dependencies. label Jul 9, 2024
@renovate renovate bot force-pushed the renovate/glob-11.x branch from 8c7d1c8 to c271f02 Compare October 13, 2024 18:51
@renovate renovate bot force-pushed the renovate/glob-11.x branch from c271f02 to db0af79 Compare August 10, 2025 14:47
Copy link

@pedroCollogno pedroCollogno left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a good update that would fix one of the indirect dependencies for the CVE-2025-5889

❯ npm ls brace-expansion
archiver-utils@5.0.2
├─┬ glob@10.4.5
│ └─┬ minimatch@9.0.5
│   └── brace-expansion@2.0.1
└─┬ mocha@10.7.3
  └─┬ minimatch@5.1.6
    └── brace-expansion@2.0.1

@renovate renovate bot force-pushed the renovate/glob-11.x branch from db0af79 to bde7029 Compare September 25, 2025 15:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Upgrade or downgrade of project dependencies.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant