Skip to content

fix(deps): Bump sinon to 21.0.1 in @sentry(ember)#19246

Merged
chargome merged 2 commits intodevelopfrom
cg/bump-sinon
Feb 10, 2026
Merged

fix(deps): Bump sinon to 21.0.1 in @sentry(ember)#19246
chargome merged 2 commits intodevelopfrom
cg/bump-sinon

Conversation

@chargome
Copy link
Member

  • Bumps sinon from 19.0.2 to 21.0.1 in packages/ember to resolve CVE-2026-24001 (DoS via
    parsePatch/applyPatch in diff)
    • This pulls in diff@^8.0.2 (patched) instead of diff@^7.0.0 (vulnerable)
    • No breaking changes affect our usage — sinon v20/v21 only removed usingPromise,
      fakeXMLHttpRequest, fakeServer, and assert.failException, none of which we use

@chargome chargome self-assigned this Feb 10, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 10, 2026

Codecov Results 📊


Generated by Codecov Action

@chargome chargome enabled auto-merge (squash) February 10, 2026 10:54
@github-actions
Copy link
Contributor

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.
⚠️ Warning: Base artifact is not the latest one, because the latest workflow run is not done yet. This may lead to incorrect results. Try to re-run all tests to get up to date results.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 8,374 - 11,784 -29%
GET With Sentry 1,710 20% 2,006 -15%
GET With Sentry (error only) 5,920 71% 7,729 -23%
POST Baseline 1,162 - 1,185 -2%
POST With Sentry 568 49% 602 -6%
POST With Sentry (error only) 1,037 89% 1,054 -2%
MYSQL Baseline 3,275 - 4,058 -19%
MYSQL With Sentry 430 13% 588 -27%
MYSQL With Sentry (error only) 2,650 81% 3,267 -19%

View base workflow run

@chargome chargome merged commit 1c9c793 into develop Feb 10, 2026
429 of 431 checks passed
@chargome chargome deleted the cg/bump-sinon branch February 10, 2026 12:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants