Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Latest sequelize-cli installs deprecated glob@10.5.0 through js-beautify

Open
#1,572 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
3/5
Estimated time
1-2 days
Newbie friendliness
68/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
javascript, node.js
Domain
cli, tooling

Research direction

Reproduce the warning with the clean npm installation described in the issue, then inspect sequelize-cli@6.6.5's js-beautify dependency and run npm explain glob to confirm the path. Evaluate the current js-beautify release or another dependency change, and verify that installation no longer includes deprecated glob@10.5.0 without breaking the CLI.

Written by the indexing model from the issue text.

Description

Bug Description

Installing the latest sequelize-cli release in a clean npm project produces a deprecation warning for glob@10.5.0.

The dependency is introduced through the following runtime dependency path:

sequelize-cli@6.6.5
└── js-beautify@1.15.4
    └── glob@10.5.0

sequelize-cli@6.6.5 depends on js-beautify@1.15.4, which declares glob@^10.4.2. That range currently resolves to the deprecated glob@10.5.0 release.

Could sequelize-cli upgrade js-beautify, replace it, or otherwise update this dependency path so that a clean installation no longer includes a deprecated glob version? The current js-beautify release uses a supported major version of glob, although upgrading it may require compatibility testing because it is a major-version change.

Reproducible Example
mkdir sequelize-cli-deprecation-reproduction
cd sequelize-cli-deprecation-reproduction
npm init -y
npm install --save-dev sequelize-cli@latest

No Sequelize configuration, application code, or database connection is required.

What do you expect to happen?

Installing the latest sequelize-cli release should not introduce runtime dependencies that their maintainers have marked as deprecated or unsupported.

What is actually happening?

The clean installation emits:

npm warn deprecated glob@10.5.0: Old versions of glob are not supported, and contain widely publicized security vulnerabilities, which have been fixed in the current version. Please update. Support for old versions may be purchased (at exorbitant rates) by contacting i@izs.me

Running npm explain glob confirms that it is introduced through js-beautify:

glob@10.5.0
node_modules/glob
  glob@"^10.4.2" from js-beautify@1.15.4
  node_modules/js-beautify
    js-beautify@"1.15.4" from sequelize-cli@6.6.5

This report concerns the unsupported dependency and installation warning. It is not asserting that glob@10.5.0 is affected by a specific unpatched security vulnerability.

Environment
  • Sequelize CLI version: 6.6.5
  • Node.js version: 24.19.0
  • npm version: 12.0.0
  • Operating system: macOS
  • Database & Version: Not applicable; reproduced during installation

Would you be willing to resolve this issue by submitting a Pull Request?

No. I understand that I will need to wait until someone from the community or the maintainers is interested in resolving the issue.

Dominant language
JavaScript
Stars
2.6k
Forks
524
PR merge metrics
No merged PRs in 30d

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from sequelize/cli

All issues in sequelize/cli

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.