Skip to content

Conversation

Copy link
Contributor

Copilot AI commented Nov 25, 2025

CVE-2025-64756 is a command injection vulnerability in glob CLI's -c/--cmd option affecting versions 10.2.0 to 10.4.5. Transitive dependency was pinned at 10.4.5 via @semantic-release/npm and pacote.

Changes

  • Added [email protected] to resolutions (yarn) and overrides (npm) in package.json
  • Updated yarn.lock to resolve all glob dependencies to 10.5.0
"overrides": {
  "glob": "10.5.0"
},
"resolutions": {
  "glob": "10.5.0"
}
Original prompt

This section details on the original issue you should resolve

<issue_title>[Vanta] Remediate "High vulnerabilities identified in packages are addressed (GitHub Repo)" for npm-glob >= 10.2.0, < 10.5.0/CVE-2025-64756 (taskforce-connector)</issue_title>
<issue_description>What's wrong?
You have open high severity vulnerabilities.

Github Vulnerability

How to fix?

  1. Visit the Vulnerabilities page to learn more about the unresolved vulnerabilities.
  2. Remediate or deactivate monitoring for each unresolved vulnerability.
  3. Optional] If the vulnerability was resolved outside of the SLA you’ve defined, explain the reason to your auditor on the [SLA violations page.

This issue was automatically created from Vanta. View test in Vanta</issue_description>

Comments on the Issue (you are @copilot in this section)


💬 We'd love your input! Share your thoughts on Copilot coding agent in our 2 minute survey.

@manast manast marked this pull request as ready for review November 25, 2025 10:40
Copilot AI review requested due to automatic review settings November 25, 2025 10:40
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copilot AI changed the title [WIP] Remediate high vulnerabilities in npm-glob for taskforce-connector fix: Remediate CVE-2025-64756 by upgrading glob to 10.5.0 Nov 25, 2025
Copilot AI requested a review from manast November 25, 2025 10:42
Copilot finished work on behalf of manast November 25, 2025 10:42
@manast manast requested a review from roggervalf November 25, 2025 14:49
@roggervalf roggervalf merged commit e80d3e5 into master Nov 26, 2025
5 of 6 checks passed
@roggervalf roggervalf deleted the copilot/remediate-high-vulnerabilities branch November 26, 2025 01:13
@github-actions
Copy link
Contributor

🎉 This PR is included in version 1.36.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

3 participants