Skip to content

Update glob - #132

Open
taylorreece wants to merge 3 commits into
calvinmetcalf:masterfrom
taylorreece:update-glob
Open

Update glob#132
taylorreece wants to merge 3 commits into
calvinmetcalf:masterfrom
taylorreece:update-glob

Conversation

@taylorreece

@taylorreece taylorreece commented Jul 11, 2024

Copy link
Copy Markdown

This updates the glob dependency to its latest version to remove a downstream deprecated dependency inflight.

Fixes #130
Fixes #133

@Tasin5541

Copy link
Copy Markdown

Would be great to have this fix merged

@stabryla-se

Copy link
Copy Markdown

Are you planning to merge ?

@taylorreece

Copy link
Copy Markdown
Author

@calvinmetcalf , thoughts on merging this?

@wysok

wysok commented Mar 13, 2025

Copy link
Copy Markdown

Will it be merged?

@Agrinden

Copy link
Copy Markdown

I have the same question.. are you planning to merge it?

@finkinfridom

Copy link
Copy Markdown

any news on this? would be ideal to have an updated version with updated dependencies

@jacquesg

Copy link
Copy Markdown

This is now a blocker, with the following vulnerability open: GHSA-5j98-mcp5-4vw2

It is really onerous to override this locally in package.json, because:

  • The glob package has gone through a few breaking changes, notably in v10, the default export has been removed.
  • The glob package is heavily depended on many packages.
  • Having different versions overridden is really painful

@taylorreece

Copy link
Copy Markdown
Author

Seems like the owner is not maintaining this project. Probably time for someone to fork it...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Deprecated glob dependency Missing Release of Resource after Effective Lifetime [Medium Severity] in copyfiles@2.4.1 > glob@7.2.3 > inflight@1.0.6

7 participants