Skip to content

Commit 0926993

Browse files
committed
chore: updating minimatch
- Adding a devDependency on minimatch in the root, so that all outdated versions get pushed into duplicates. - Updated `minimatch` direct dependency packages/node, packages/react-router, and packages/remix - Once getsentry/sentry-javascript-bundler-plugins#885 lands, we can update the dependency coming in from `@sentry/bundler-plugin-core` There are several other dependencies that transitively bring in a minimatch v3, v5, v8, or v9. Fixes for the ReDOS will be backported where those dependencies cannot be easily updated.
1 parent 53e6b63 commit 0926993

File tree

5 files changed

+49
-8
lines changed

5 files changed

+49
-8
lines changed

package.json

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -127,15 +127,16 @@
127127
"es-check": "^7.2.1",
128128
"eslint": "8.57.0",
129129
"jsdom": "^21.1.2",
130-
"nx": "22.5.0",
131130
"madge": "8.0.0",
131+
"minimatch": "^10.2.2",
132132
"nodemon": "^3.1.10",
133133
"npm-run-all2": "^6.2.0",
134+
"nx": "22.5.0",
134135
"oxfmt": "^0.32.0",
135136
"rimraf": "^5.0.10",
136-
"rollup": "^4.35.0",
137137
"rollup-plugin-cleanup": "^3.2.1",
138138
"rollup-plugin-license": "^3.3.1",
139+
"rollup": "^4.35.0",
139140
"size-limit": "~11.1.6",
140141
"sucrase": "^3.35.0",
141142
"ts-node": "10.9.2",

packages/node/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -99,7 +99,7 @@
9999
"@sentry/node-core": "10.39.0",
100100
"@sentry/opentelemetry": "10.39.0",
101101
"import-in-the-middle": "^2.0.6",
102-
"minimatch": "^9.0.0"
102+
"minimatch": "^10.2.2"
103103
},
104104
"devDependencies": {
105105
"@types/node": "^18.19.1"

packages/react-router/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@
5555
"@sentry/node": "10.39.0",
5656
"@sentry/react": "10.39.0",
5757
"@sentry/vite-plugin": "^4.8.0",
58-
"glob": "^13.0.1"
58+
"glob": "^13.0.6"
5959
},
6060
"devDependencies": {
6161
"@react-router/dev": "^7.13.0",

packages/remix/package.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -72,7 +72,7 @@
7272
"@sentry/core": "10.39.0",
7373
"@sentry/node": "10.39.0",
7474
"@sentry/react": "10.39.0",
75-
"glob": "^10.3.4",
75+
"glob": "^13.0.6",
7676
"yargs": "^17.6.0"
7777
},
7878
"devDependencies": {

yarn.lock

Lines changed: 43 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12447,6 +12447,11 @@ balanced-match@^1.0.0:
1244712447
resolved "https://registry.yarnpkg.com/balanced-match/-/balanced-match-1.0.2.tgz#e83e3a7e3f300b34cb9d87f615fa0cbf357690ee"
1244812448
integrity sha512-3oSeUO0TMV67hN1AmbXsK4yaqU7tjiHlbxRDZOpH0KW9+CeX4bRAaX0Anxt0tx2MrpRpWwQaPwIlISEJhYU5Pw==
1244912449

12450+
balanced-match@^4.0.2:
12451+
version "4.0.3"
12452+
resolved "https://registry.yarnpkg.com/balanced-match/-/balanced-match-4.0.3.tgz#6337a2f23e0604a30481423432f99eac603599f9"
12453+
integrity sha512-1pHv8LX9CpKut1Zp4EXey7Z8OfH11ONNH6Dhi2WDUt31VVZFXZzKwXcysBgqSumFCmR+0dqjMK5v5JiFHzi0+g==
12454+
1245012455
bare-events@^2.2.0, bare-events@^2.5.4:
1245112456
version "2.5.4"
1245212457
resolved "https://registry.yarnpkg.com/bare-events/-/bare-events-2.5.4.tgz#16143d435e1ed9eafd1ab85f12b89b3357a41745"
@@ -12774,6 +12779,13 @@ brace-expansion@^2.0.1:
1277412779
dependencies:
1277512780
balanced-match "^1.0.0"
1277612781

12782+
brace-expansion@^5.0.2:
12783+
version "5.0.2"
12784+
resolved "https://registry.yarnpkg.com/brace-expansion/-/brace-expansion-5.0.2.tgz#b6c16d0791087af6c2bc463f52a8142046c06b6f"
12785+
integrity sha512-Pdk8c9poy+YhOgVWw1JNN22/HcivgKWwpxKq04M/jTmHyCZn12WPJebZxdjSa5TmBqISrUSgNYU3eRORljfCCw==
12786+
dependencies:
12787+
balanced-match "^4.0.2"
12788+
1277712789
braces@^2.3.1:
1277812790
version "2.3.2"
1277912791
resolved "https://registry.yarnpkg.com/braces/-/braces-2.3.2.tgz#5979fd3f14cd531565e5fa2df1abfff1dfaee729"
@@ -18499,7 +18511,7 @@ glob@8.0.3:
1849918511
minimatch "^5.0.1"
1850018512
once "^1.3.0"
1850118513

18502-
glob@^10.0.0, glob@^10.3.10, glob@^10.3.4, glob@^10.3.7, glob@^10.4.1, glob@^10.5.0:
18514+
glob@^10.0.0, glob@^10.3.10, glob@^10.3.7, glob@^10.4.1, glob@^10.5.0:
1850318515
version "10.5.0"
1850418516
resolved "https://registry.yarnpkg.com/glob/-/glob-10.5.0.tgz#8ec0355919cd3338c28428a23d4f24ecc5fe738c"
1850518517
integrity sha512-DfXN8DfhJ7NH3Oe7cFmu3NCu1wKbkReJ8TorzSAFbSKrlNaQSKfIzqYqVY8zlbs2NLBbWpRiU52GX2PbaBVNkg==
@@ -18511,7 +18523,7 @@ glob@^10.0.0, glob@^10.3.10, glob@^10.3.4, glob@^10.3.7, glob@^10.4.1, glob@^10.
1851118523
package-json-from-dist "^1.0.0"
1851218524
path-scurry "^1.11.1"
1851318525

18514-
glob@^13.0.0, glob@^13.0.1:
18526+
glob@^13.0.0:
1851518527
version "13.0.1"
1851618528
resolved "https://registry.yarnpkg.com/glob/-/glob-13.0.1.tgz#c59a2500c9a5f1ab9cdd370217ced63c2aa81e60"
1851718529
integrity sha512-B7U/vJpE3DkJ5WXTgTpTRN63uV42DseiXXKMwG14LQBXmsdeIoHAPbU/MEo6II0k5ED74uc2ZGTC6MwHFQhF6w==
@@ -18520,6 +18532,15 @@ glob@^13.0.0, glob@^13.0.1:
1852018532
minipass "^7.1.2"
1852118533
path-scurry "^2.0.0"
1852218534

18535+
glob@^13.0.6:
18536+
version "13.0.6"
18537+
resolved "https://registry.yarnpkg.com/glob/-/glob-13.0.6.tgz#078666566a425147ccacfbd2e332deb66a2be71d"
18538+
integrity sha512-Wjlyrolmm8uDpm/ogGyXZXb1Z+Ca2B8NbJwqBVg0axK9GbBeoS7yGV6vjXnYdGm6X53iehEuxxbyiKp8QmN4Vw==
18539+
dependencies:
18540+
minimatch "^10.2.2"
18541+
minipass "^7.1.3"
18542+
path-scurry "^2.0.2"
18543+
1852318544
glob@^5.0.10:
1852418545
version "5.0.15"
1852518546
resolved "https://registry.yarnpkg.com/glob/-/glob-5.0.15.tgz#1bc936b9e02f4a603fcc222ecf7633d30b8b93b1"
@@ -22497,6 +22518,13 @@ minimatch@^10.1.2:
2249722518
dependencies:
2249822519
"@isaacs/brace-expansion" "^5.0.1"
2249922520

22521+
minimatch@^10.2.2:
22522+
version "10.2.2"
22523+
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-10.2.2.tgz#361603ee323cfb83496fea2ae17cc44ea4e1f99f"
22524+
integrity sha512-+G4CpNBxa5MprY+04MbgOw1v7So6n5JY166pFi9KfYwT78fxScCeSNQSNzp6dpPSW2rONOps6Ocam1wFhCgoVw==
22525+
dependencies:
22526+
brace-expansion "^5.0.2"
22527+
2250022528
minimatch@^7.4.1:
2250122529
version "7.4.6"
2250222530
resolved "https://registry.yarnpkg.com/minimatch/-/minimatch-7.4.6.tgz#845d6f254d8f4a5e4fd6baf44d5f10c8448365fb"
@@ -22612,6 +22640,11 @@ minipass@^5.0.0:
2261222640
resolved "https://registry.yarnpkg.com/minipass/-/minipass-7.1.2.tgz#93a9626ce5e5e66bd4db86849e7515e92340a707"
2261322641
integrity sha512-qOOzS1cBTWYF4BH8fVePDBOO9iptMnGUEZwNc/cMWnTV2nVLZ7VoNWEPHkYczZA0pdoA7dl6e7FL659nX9S2aw==
2261422642

22643+
minipass@^7.1.3:
22644+
version "7.1.3"
22645+
resolved "https://registry.yarnpkg.com/minipass/-/minipass-7.1.3.tgz#79389b4eb1bb2d003a9bba87d492f2bd37bdc65b"
22646+
integrity sha512-tEBHqDnIoM/1rXME1zgka9g6Q2lcoCkxHLuc7ODJ5BxbP5d4c2Z5cGgtXAku59200Cx7diuHTOYfSBD8n6mm8A==
22647+
2261522648
minizlib@^2.1.1, minizlib@^2.1.2:
2261622649
version "2.1.2"
2261722650
resolved "https://registry.yarnpkg.com/minizlib/-/minizlib-2.1.2.tgz#e90d3466ba209b932451508a11ce3d3632145931"
@@ -24557,6 +24590,14 @@ path-scurry@^2.0.0:
2455724590
lru-cache "^11.0.0"
2455824591
minipass "^7.1.2"
2455924592

24593+
path-scurry@^2.0.2:
24594+
version "2.0.2"
24595+
resolved "https://registry.yarnpkg.com/path-scurry/-/path-scurry-2.0.2.tgz#6be0d0ee02a10d9e0de7a98bae65e182c9061f85"
24596+
integrity sha512-3O/iVVsJAPsOnpwWIeD+d6z/7PmqApyQePUtCndjatj/9I5LylHvt5qluFaBT3I5h3r1ejfR056c+FCv+NnNXg==
24597+
dependencies:
24598+
lru-cache "^11.0.0"
24599+
minipass "^7.1.2"
24600+
2456024601
path-to-regexp@0.1.12, path-to-regexp@~0.1.12:
2456124602
version "0.1.12"
2456224603
resolved "https://registry.yarnpkg.com/path-to-regexp/-/path-to-regexp-0.1.12.tgz#d5e1a12e478a976d432ef3c58d534b9923164bb7"
@@ -28692,7 +28733,6 @@ stylus@0.59.0, stylus@^0.59.0:
2869228733

2869328734
sucrase@^3.27.0, sucrase@^3.35.0, sucrase@getsentry/sucrase#es2020-polyfills:
2869428735
version "3.36.0"
28695-
uid fd682f6129e507c00bb4e6319cc5d6b767e36061
2869628736
resolved "https://codeload.github.com/getsentry/sucrase/tar.gz/fd682f6129e507c00bb4e6319cc5d6b767e36061"
2869728737
dependencies:
2869828738
"@jridgewell/gen-mapping" "^0.3.2"

0 commit comments

Comments
 (0)