plugins icon indicating copy to clipboard operation
plugins copied to clipboard

chore(commonjs): bump glob's version

Open younggglcy opened this issue 1 year ago • 1 comments

Rollup Plugin Name: @rollup/plugin-commonjs

This PR contains:

  • [x] bugfix
  • [ ] feature
  • [ ] refactor
  • [ ] documentation
  • [x] other

Are tests included?

  • [ ] yes (bugfixes and features will not be merged without tests)
  • [x] no

Breaking Changes?

  • [x] yes (breaking changes will not be merged unless absolutely necessary)
  • [ ] no

If yes, then include "BREAKING CHANGES:" in the first commit message body, followed by a description of what is breaking.

List any relevant issue numbers: resolves #1691

Description

BREAKING CHANGES: Requires Node.js version >=16.0.0 or >= 14.17, this is the same as glob's need.

both glob and shx have inflight in their deps, so this PR bumps glob to the latest and removes shx, since it's not been used.

younggglcy avatar Mar 17 '24 12:03 younggglcy

Hi any update on this? There is a vulnerability introduced thought this

akashennn avatar Apr 05 '24 03:04 akashennn

Hello, any updates on this? or is there a workaround Facing this issue:

warning nuxt > nitropack > @rollup/plugin-commonjs > glob > [email protected]: This module is not supported, and leaks memory. Do not use it. Check out lru-cache if you want a good and tested way to coalesce async requests by a key value, which is much more comprehensive and powerful.91

mehdibo avatar May 27 '24 11:05 mehdibo

CI tests failed due to wrong order returned by glob.sync() here. That's because, since glob v9, results will not be sorted. FYI: https://github.com/isaacs/node-glob/issues/576

younggglcy avatar May 27 '24 13:05 younggglcy

@younggglcy I think this is good to merge, but please rebase/merge from master again. CI isn't happy.

shellscape avatar Jun 05 '24 01:06 shellscape

@younggglcy I think this is good to merge, but please rebase/merge from master again. CI isn't happy.

fixed.

younggglcy avatar Jun 05 '24 05:06 younggglcy