Skip to content

chore(deps): Bump Lerna to v9#19244

Merged
chargome merged 1 commit intodevelopfrom
cg/bump-lerna
Feb 10, 2026
Merged

chore(deps): Bump Lerna to v9#19244
chargome merged 1 commit intodevelopfrom
cg/bump-lerna

Conversation

@chargome
Copy link
Member

  • Bumps lerna from 8.2.4 to 9.0.3 to resolve
    CVE-2025-64718
    (medium severity prototype pollution in js-yaml)
  • lerna@8.2.4 pulled in js-yaml@4.1.0 (vulnerable); lerna@9.0.3 depends on
    js-yaml@4.1.1 (patched)
  • Lerna 9 drops support for Node <18.18.0. This doesn't affect us — lerna runs in the root
    workspace context using Volta's pinned Node 20.19.2. The engines: >=18 fields in dev-packages
    are runtime compatibility declarations, not what CI uses to run lerna.

Resolves https://github.com/getsentry/sentry-javascript/security/dependabot/789

@chargome chargome requested a review from JPeer264 February 10, 2026 10:05
@chargome chargome self-assigned this Feb 10, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 10, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 11,266 - 11,850 -5%
GET With Sentry 1,983 18% 2,065 -4%
GET With Sentry (error only) 7,574 67% 7,827 -3%
POST Baseline 1,167 - 1,293 -10%
POST With Sentry 585 50% 643 -9%
POST With Sentry (error only) 1,035 89% 1,166 -11%
MYSQL Baseline 3,939 - 3,564 +11%
MYSQL With Sentry 529 13% 528 +0%
MYSQL With Sentry (error only) 3,193 81% 3,057 +4%

View base workflow run

Copy link
Member

@andreiborza andreiborza left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📿

@chargome chargome merged commit 57a048d into develop Feb 10, 2026
221 checks passed
@chargome chargome deleted the cg/bump-lerna branch February 10, 2026 10:40
JPeer264 added a commit that referenced this pull request Feb 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants