Skip to content

feat(deps): Bump glob in @sentry/react-router#19162

Merged
chargome merged 3 commits intogetsentry:developfrom
rfoel:rfoel/glob-bump
Feb 5, 2026
Merged

feat(deps): Bump glob in @sentry/react-router#19162
chargome merged 3 commits intogetsentry:developfrom
rfoel:rfoel/glob-bump

Conversation

@rfoel
Copy link
Contributor

@rfoel rfoel commented Feb 4, 2026

Bumps glob from 11.1.0 to 13.0.1 in @sentry/react-router to resolve a security vulnerability in the transitive dependency @isaacs/brace-expansion.

Dependency chain: @sentry/react-routerglobminimatch@isaacs/brace-expansion

Details
The previous version of glob (11.1.0) pulled in a vulnerable version of @isaacs/brace-expansion. The vulnerability has been patched upstream:

@isaacs/brace-expansion was patched
minimatch released a new version with the fix
glob 13.0.1 includes the updated dependencies
This is a dependency-only change with no code modifications.

CVE

@Lms24 Lms24 requested a review from chargome February 4, 2026 16:34
Copy link
Member

@Lms24 Lms24 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for submitting this PR! Sounds reasonable to me to bump this. @chargome any concerns regarding the major bumps? I don't think any of the breaking changes apply to RR.

Copy link

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.

"@sentry/react": "10.38.0",
"@sentry/vite-plugin": "^4.8.0",
"glob": "11.1.0"
"glob": "13.0.1"
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Glob v13 may break CJS consumers

High Severity

Upgrading glob to 13.0.1 may introduce a breaking runtime change for CommonJS consumers of @sentry/react-router if glob’s v13 exports/module format no longer supports require() or behaves differently in CJS (notably for array patterns passed to glob() in sentryOnBuildEnd).

Additional Locations (1)

Fix in Cursor Fix in Web

Copy link
Member

@chargome chargome left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This one is just used for onBuildEnd so we should be fine, thanks for contributing!

@chargome chargome changed the title Bump glob in @sentry/react-router feat(deps): Bump glob in @sentry/react-router Feb 5, 2026
"@sentry/react": "10.38.0",
"@sentry/vite-plugin": "^4.8.0",
"glob": "11.1.0"
"glob": "13.0.1"
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
"glob": "13.0.1"
"glob": "^13.0.1"

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@rfoel please apply this and re-run yarn before merging in

@chargome chargome merged commit 7256d9e into getsentry:develop Feb 5, 2026
195 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants