Bug Description
Installing the latest sequelize-cli release in a clean npm project produces a deprecation warning for glob@10.5.0.
The dependency is introduced through the following runtime dependency path:
sequelize-cli@6.6.5
└── js-beautify@1.15.4
└── glob@10.5.0
sequelize-cli@6.6.5 depends on js-beautify@1.15.4, which declares glob@^10.4.2. That range currently resolves to the deprecated glob@10.5.0 release.
Could sequelize-cli upgrade js-beautify, replace it, or otherwise update this dependency path so that a clean installation no longer includes a deprecated glob version? The current js-beautify release uses a supported major version of glob, although upgrading it may require compatibility testing because it is a major-version change.
Reproducible Example
mkdir sequelize-cli-deprecation-reproduction
cd sequelize-cli-deprecation-reproduction
npm init -y
npm install --save-dev sequelize-cli@latest
No Sequelize configuration, application code, or database connection is required.
What do you expect to happen?
Installing the latest sequelize-cli release should not introduce runtime dependencies that their maintainers have marked as deprecated or unsupported.
What is actually happening?
The clean installation emits:
npm warn deprecated glob@10.5.0: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me
Running npm explain glob confirms that it is introduced through js-beautify:
glob@10.5.0
node_modules/glob
glob@"^10.4.2" from js-beautify@1.15.4
node_modules/js-beautify
js-beautify@"1.15.4" from sequelize-cli@6.6.5
This report concerns the unsupported dependency and installation warning. It is not asserting that glob@10.5.0 is affected by a specific unpatched security vulnerability.
Environment
- Sequelize CLI version:
6.6.5
- Node.js version:
24.19.0
- npm version:
12.0.0
- Operating system: macOS
- Database & Version: Not applicable; reproduced during installation
Would you be willing to resolve this issue by submitting a Pull Request?
No. I understand that I will need to wait until someone from the community or the maintainers is interested in resolving the issue.
Bug Description
Installing the latest
sequelize-clirelease in a clean npm project produces a deprecation warning forglob@10.5.0.The dependency is introduced through the following runtime dependency path:
sequelize-cli@6.6.5depends onjs-beautify@1.15.4, which declaresglob@^10.4.2. That range currently resolves to the deprecatedglob@10.5.0release.Could
sequelize-cliupgradejs-beautify, replace it, or otherwise update this dependency path so that a clean installation no longer includes a deprecatedglobversion? The currentjs-beautifyrelease uses a supported major version ofglob, although upgrading it may require compatibility testing because it is a major-version change.Reproducible Example
mkdir sequelize-cli-deprecation-reproduction cd sequelize-cli-deprecation-reproduction npm init -y npm install --save-dev sequelize-cli@latestNo Sequelize configuration, application code, or database connection is required.
What do you expect to happen?
Installing the latest
sequelize-clirelease should not introduce runtime dependencies that their maintainers have marked as deprecated or unsupported.What is actually happening?
The clean installation emits:
Running
npm explain globconfirms that it is introduced throughjs-beautify:This report concerns the unsupported dependency and installation warning. It is not asserting that
glob@10.5.0is affected by a specific unpatched security vulnerability.Environment
6.6.524.19.012.0.0Would you be willing to resolve this issue by submitting a Pull Request?
No. I understand that I will need to wait until someone from the community or the maintainers is interested in resolving the issue.