Bump glob to v13 and rollup to v4.59+ to fix security vulnerabilities
Addresses the high severity rollup path traversal vulnerability (GHSA-mw96-cpmx-2vgc) and the glob security advisory by upgrading all instances across the monorepo. Updates code that used the legacy callback-based glob API to use the modern promise/sync API. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Signed-off-by: Fredrik Adelöw <freben@spotify.com>
This commit is contained in:
@@ -37,7 +37,7 @@
|
||||
"@backstage/errors": "workspace:^",
|
||||
"cleye": "^2.3.0",
|
||||
"fs-extra": "^11.2.0",
|
||||
"glob": "^7.1.7",
|
||||
"glob": "^13.0.0",
|
||||
"inquirer": "^8.2.0",
|
||||
"proper-lockfile": "^4.1.2",
|
||||
"yaml": "^2.0.0",
|
||||
|
||||
@@ -31,7 +31,7 @@ import { getSecretStore, getAuthInstanceService } from '@internal/cli';
|
||||
import crypto from 'node:crypto';
|
||||
import fs from 'fs-extra';
|
||||
import path from 'node:path';
|
||||
import glob from 'glob';
|
||||
import { globSync } from 'glob';
|
||||
import YAML from 'yaml';
|
||||
import inquirer from 'inquirer';
|
||||
|
||||
@@ -178,7 +178,7 @@ async function pickBaseUrl() {
|
||||
'packages/*/app-config.yaml',
|
||||
'packages/*/app-config.*.yaml',
|
||||
];
|
||||
const files = patterns.flatMap(p => glob.sync(p, { cwd, nodir: true }));
|
||||
const files = patterns.flatMap(p => globSync(p, { cwd, nodir: true }));
|
||||
for (const file of files) {
|
||||
try {
|
||||
const content = await fs.readFile(path.resolve(cwd, file), 'utf8');
|
||||
|
||||
Reference in New Issue
Block a user