Skip to content

Conversation

@JPeer264
Copy link
Member

@JPeer264 JPeer264 commented Nov 20, 2025

closes #822

We were not affected, since v9 was not part of it. However, I updated this packages just in case. v10.5.0 is the latest version which is supporting v18, which we use here. To not touch too much code I used this version (which is also in the range of the fixed versions)

Copy link
Member

@andreiborza andreiborza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks for taking care of it!

@JPeer264 JPeer264 merged commit c98c833 into main Nov 20, 2025
24 checks passed
@JPeer264 JPeer264 deleted the jp/update-glob branch November 20, 2025 09:55
renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request Nov 20, 2025
| datasource | package             | from  | to    |
| ---------- | ------------------- | ----- | ----- |
| npm        | @sentry/vite-plugin | 4.6.0 | 4.6.1 |


## [v4.6.1](https://github.com/getsentry/sentry-javascript-bundler-plugins/blob/HEAD/CHANGELOG.md#461)

- chore(deps): Update glob to 10.5.0 ([#823](getsentry/sentry-javascript-bundler-plugins#823))

<details>
  <summary> <strong>Internal Changes</strong> </summary>

- chore(core): Log release output ([#821](getsentry/sentry-javascript-bundler-plugins#821))

</details>
renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request Nov 21, 2025
| datasource | package             | from  | to    |
| ---------- | ------------------- | ----- | ----- |
| npm        | @sentry/vite-plugin | 4.6.0 | 4.6.1 |


## [v4.6.1](https://github.com/getsentry/sentry-javascript-bundler-plugins/blob/HEAD/CHANGELOG.md#461)

- chore(deps): Update glob to 10.5.0 ([#823](getsentry/sentry-javascript-bundler-plugins#823))

<details>
  <summary> <strong>Internal Changes</strong> </summary>

- chore(core): Log release output ([#821](getsentry/sentry-javascript-bundler-plugins#821))

</details>
renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request Nov 22, 2025
| datasource | package             | from  | to    |
| ---------- | ------------------- | ----- | ----- |
| npm        | @sentry/vite-plugin | 4.6.0 | 4.6.1 |


## [v4.6.1](https://github.com/getsentry/sentry-javascript-bundler-plugins/blob/HEAD/CHANGELOG.md#461)

- chore(deps): Update glob to 10.5.0 ([#823](getsentry/sentry-javascript-bundler-plugins#823))

<details>
  <summary> <strong>Internal Changes</strong> </summary>

- chore(core): Log release output ([#821](getsentry/sentry-javascript-bundler-plugins#821))

</details>
renovate bot added a commit to andrei-picus-tink/auto-renovate that referenced this pull request Nov 23, 2025
| datasource | package             | from  | to    |
| ---------- | ------------------- | ----- | ----- |
| npm        | @sentry/vite-plugin | 4.6.0 | 4.6.1 |


## [v4.6.1](https://github.com/getsentry/sentry-javascript-bundler-plugins/blob/HEAD/CHANGELOG.md#461)

- chore(deps): Update glob to 10.5.0 ([#823](getsentry/sentry-javascript-bundler-plugins#823))

<details>
  <summary> <strong>Internal Changes</strong> </summary>

- chore(core): Log release output ([#821](getsentry/sentry-javascript-bundler-plugins#821))

</details>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

glob vulnerability in @sentry/bundler-plugin-core

3 participants