Repository navigation
Use glob's unbundled entry point to avoid a stale bundled minimatch - #2510
Merged
Merged
Conversation
glob's default export is a pre-bundled minified file with its own minimatch copy baked in at build time, so bumping or deduping the minimatch version we depend on has no effect on it. glob/raw resolves minimatch normally instead, so security patches actually apply. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
GabrielAnca
force-pushed
the
gabriel.anca/fix-junit-glob-minimatch-redos
branch
from
September 11, 2026 15:30
d147fbd to
71d9808
Compare
GabrielAnca
marked this pull request as ready for review
September 11, 2026 15:32
|
🔗 Commit SHA: 615992b | Docs | View more details | Give us feedback! |
Drarig29
approved these changes
Sep 11, 2026
Drarig29
left a comment
Collaborator
There was a problem hiding this comment.
Confirmed with a new E2E test that this will work as intended, even once our own packages are bundled.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why?
glob's default entry point is a pre-bundled minified file that has its own copy ofminimatchbaked in at build time. That embedded copy is currently a vulnerable 10.2.2 version, and bumping or deduping theminimatchversion in our own dependency tree has no effect on it, since the bundled file never actually resolvesminimatchthrough node's module resolution.How?
Switch our shared glob helper (used by
plugin-junit,plugin-sarif,plugin-coverage, andplugin-synthetics) to import fromglob/rawinstead ofglob. That entry point is unbundled and resolvesminimatchnormally, so the patched version we already depend on is what actually runs.See glob's source where the default and
rawexports are defined.Review checklist