Skip to content

fix: update glob package to address security vulnerability#1301

Merged
vcnainala merged 4 commits intomainfrom
glob-cli-security-issue
Dec 3, 2025
Merged

fix: update glob package to address security vulnerability#1301
vcnainala merged 4 commits intomainfrom
glob-cli-security-issue

Conversation

@NishaSharma14
Copy link
Copy Markdown
Contributor

No description provided.

Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the glob package from version 10.4.5 to 10.5.0 to address a security vulnerability. The update includes corresponding updates to related dependencies (js-yaml, mdast-util-to-hast, jiti, vite) and a complete rebuild of the frontend assets, as reflected in the build manifest.

Key Changes:

  • Updated glob package to address security vulnerability (10.4.5 → 10.5.0)
  • Updated related dependencies to maintain compatibility
  • Regenerated frontend build artifacts

Reviewed changes

Copilot reviewed 1 out of 4 changed files in this pull request and generated no comments.

File Description
package.json Updates tailwindcss from ^3.2.4 to ^3.4.18
package-lock.json Updates glob, js-yaml, mdast-util-to-hast, vite, and tailwindcss with new versions and adds package name field
yarn.lock Updates glob, jiti, js-yaml, mdast-util-to-hast, tailwindcss, and vite dependencies
public/build/manifest.json Regenerated build manifest with new asset hashes after dependency updates

@NishaSharma14 NishaSharma14 self-assigned this Dec 3, 2025
@vcnainala vcnainala merged commit c08cc35 into main Dec 3, 2025
4 checks passed
@vcnainala vcnainala deleted the glob-cli-security-issue branch December 3, 2025 10:39
@NishaSharma14 NishaSharma14 restored the glob-cli-security-issue branch December 3, 2025 12:28
@NishaSharma14 NishaSharma14 deleted the glob-cli-security-issue branch December 3, 2025 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants