WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@rBangay
Copy link
Contributor

@rBangay rBangay commented Nov 27, 2025

What does this change?

Forces an update to the peer dependency glob, this is in order to fix the following vulnerability: https://github.com/guardian/gateway/security/dependabot/123

Unfortunately at the time of creating this pr there weren't available updates to the core dependencies that rely on glob, so we had to make changes to the lock file (using pnpm up glob) in order to force the glob version.

…At the time of this commit there weren't available updates to the core dependencies that rely on glob
@rBangay rBangay requested a review from a team as a code owner November 27, 2025 12:39
@pvighi
Copy link
Contributor

pvighi commented Nov 27, 2025

looks ok to me in CODE

@pvighi pvighi merged commit 7a1093c into main Nov 27, 2025
72 of 99 checks passed
@pvighi pvighi deleted the dependency-vuln-glob branch November 27, 2025 15:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants