Skip to content

Conversation

@weppos
Copy link
Member

@weppos weppos commented Feb 7, 2026

Summary

  • Upgrade glob from 10.4.5 to 10.5.0 to fix CVE-2025-64756 (high severity command injection in the glob CLI -c/--cmd option)
  • Regenerated yarn.lock — the existing semver ranges (^10.3.10, ^10.4.2) already allowed 10.5.0, only the lockfile pin needed updating
  • glob@^7.1.4 (used by test-exclude) correctly remains at 7.2.3 (not affected by this CVE)

Resolves https://github.com/dnsimple/dnsimple-support/security/dependabot/113

Test plan

  • All 48 existing tests pass
  • Verify CI passes

Fix CVE-2025-64756 (GHSA-5j98-mcp5-4vw2), a command injection
vulnerability in the glob CLI -c/--cmd option.
@weppos weppos self-assigned this Feb 7, 2026
@weppos weppos merged commit 9c74ec3 into main Feb 7, 2026
5 checks passed
@weppos weppos deleted the bump-glob-10.5.0 branch February 7, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant