Skip to content

Latest sequelize-cli installs deprecated glob@10.5.0 through js-beautify #1572

Description

@mmtdm

Bug Description

Installing the latest sequelize-cli release in a clean npm project produces a deprecation warning for glob@10.5.0.

The dependency is introduced through the following runtime dependency path:

sequelize-cli@6.6.5
└── js-beautify@1.15.4
    └── glob@10.5.0

sequelize-cli@6.6.5 depends on js-beautify@1.15.4, which declares glob@^10.4.2. That range currently resolves to the deprecated glob@10.5.0 release.

Could sequelize-cli upgrade js-beautify, replace it, or otherwise update this dependency path so that a clean installation no longer includes a deprecated glob version? The current js-beautify release uses a supported major version of glob, although upgrading it may require compatibility testing because it is a major-version change.

Reproducible Example

mkdir sequelize-cli-deprecation-reproduction
cd sequelize-cli-deprecation-reproduction
npm init -y
npm install --save-dev sequelize-cli@latest

No Sequelize configuration, application code, or database connection is required.

What do you expect to happen?

Installing the latest sequelize-cli release should not introduce runtime dependencies that their maintainers have marked as deprecated or unsupported.

What is actually happening?

The clean installation emits:

npm warn deprecated glob@10.5.0: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me

Running npm explain glob confirms that it is introduced through js-beautify:

glob@10.5.0
node_modules/glob
  glob@"^10.4.2" from js-beautify@1.15.4
  node_modules/js-beautify
    js-beautify@"1.15.4" from sequelize-cli@6.6.5

This report concerns the unsupported dependency and installation warning. It is not asserting that glob@10.5.0 is affected by a specific unpatched security vulnerability.

Environment

  • Sequelize CLI version: 6.6.5
  • Node.js version: 24.19.0
  • npm version: 12.0.0
  • Operating system: macOS
  • Database & Version: Not applicable; reproduced during installation

Would you be willing to resolve this issue by submitting a Pull Request?

No. I understand that I will need to wait until someone from the community or the maintainers is interested in resolving the issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions