Skip to content

Use glob's unbundled entry point to avoid a stale bundled minimatch - #2510

Merged
GabrielAnca merged 2 commits into
masterfrom
gabriel.anca/fix-junit-glob-minimatch-redos
Sep 14, 2026
Merged

GabrielAnca merged 2 commits into
masterfrom
gabriel.anca/fix-junit-glob-minimatch-redos

Conversation

@GabrielAnca

@GabrielAnca GabrielAnca commented Sep 11, 2026 •

Copy link
Copy Markdown
Collaborator

What and why?

glob's default entry point is a pre-bundled minified file that has its own copy of minimatch baked in at build time. That embedded copy is currently a vulnerable 10.2.2 version, and bumping or deduping the minimatch version in our own dependency tree has no effect on it, since the bundled file never actually resolves minimatch through node's module resolution.

How?

Switch our shared glob helper (used by plugin-junit, plugin-sarif, plugin-coverage, and plugin-synthetics) to import from glob/raw instead of glob. That entry point is unbundled and resolves minimatch normally, so the patched version we already depend on is what actually runs.

See glob's source where the default and raw exports are defined.

Review checklist

  • Feature or bugfix MUST have appropriate tests (unit, integration)

@GabrielAnca GabrielAnca added the dependencies Pull requests that update a dependency file label Sep 11, 2026
glob's default export is a pre-bundled minified file with its own
minimatch copy baked in at build time, so bumping or deduping the
minimatch version we depend on has no effect on it. glob/raw resolves
minimatch normally instead, so security patches actually apply.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@GabrielAnca
GabrielAnca force-pushed the gabriel.anca/fix-junit-glob-minimatch-redos branch from d147fbd to 71d9808 Compare September 11, 2026 15:30
@GabrielAnca
GabrielAnca marked this pull request as ready for review September 11, 2026 15:32
@GabrielAnca
GabrielAnca requested a review from a team as a code owner September 11, 2026 15:32
@datadog-prod-us1-3

datadog-prod-us1-3 Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Pipelines

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 615992b | Docs | View more details | Give us feedback!

@Drarig29 Drarig29 left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed with a new E2E test that this will work as intended, even once our own packages are bundled.

@GabrielAnca
GabrielAnca merged commit 0263838 into master Sep 14, 2026
64 of 65 checks passed
@GabrielAnca
GabrielAnca deleted the gabriel.anca/fix-junit-glob-minimatch-redos branch September 14, 2026 08:11
@Drarig29 Drarig29 mentioned this pull request Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants