Skip to content

Bump glob from 12.0.0 to 13.0.0#2722

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/glob-13.0.0
Open

Bump glob from 12.0.0 to 13.0.0#2722
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/glob-13.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 24, 2026

Bumps glob from 12.0.0 to 13.0.0.

Changelog

Sourced from glob's changelog.

changeglob

13

  • Move the CLI program out to a separate package, glob-bin. Install that if you'd like to continue using glob from the command line.

12

  • Remove the unsafe --shell option. The --shell option is now ONLY supported on known shells where the behavior can be implemented safely.

11.1

GHSA-5j98-mcp5-4vw2

  • Add the --shell option for the command line, with a warning that this is unsafe. (It will be removed in v12.)
  • Add the --cmd-arg/-g as a way to safely add positional arguments to the command provided to the CLI tool.
  • Detect commands with space or quote characters on known shells, and pass positional arguments to them safely, avoiding shell:true execution.

11.0

  • Drop support for node before v20

10.4

  • Add includeChildMatches: false option
  • Export the Ignore class

10.3

  • Add --default -p flag to provide a default pattern
  • exclude symbolic links to directories when follow and nodir are both set

10.2

  • Add glob cli

10.1

  • Return '.' instead of the empty string '' when the current working directory is returned as a match.
  • Add posix: true option to return / delimited paths, even on

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Apr 24, 2026
Copilot AI review requested due to automatic review settings April 24, 2026 15:37
@dependabot dependabot Bot added javascript Pull requests that update Javascript code dependencies Pull requests that update a dependency file labels Apr 24, 2026
@dependabot dependabot Bot review requested due to automatic review settings April 24, 2026 15:37
@dependabot dependabot Bot added the javascript Pull requests that update Javascript code label Apr 24, 2026
@socket-security
Copy link
Copy Markdown

socket-security Bot commented Apr 24, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​glob@​12.0.0 ⏵ 13.0.0100 +110010085100

View full report

Copilot AI review requested due to automatic review settings April 24, 2026 17:55
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/glob-13.0.0 branch from 846f3e3 to 0276732 Compare April 24, 2026 17:55
@dependabot dependabot Bot review requested due to automatic review settings April 24, 2026 17:55
Bumps [glob](https://github.com/isaacs/node-glob) from 12.0.0 to 13.0.0.
- [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md)
- [Commits](isaacs/node-glob@v12.0.0...v13.0.0)

---
updated-dependencies:
- dependency-name: glob
  dependency-version: 13.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/glob-13.0.0 branch from 0276732 to ce9561d Compare May 12, 2026 00:41
Copilot AI review requested due to automatic review settings May 12, 2026 00:41
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant