Skip to content

Conversation

@RulaKhaled
Copy link
Member

@RulaKhaled RulaKhaled commented Feb 2, 2026

Attempt to fix dependabot alert https://github.com/getsentry/sentry-javascript/security/dependabot/960

Closes #19139 (added automatically)

@github-actions
Copy link
Contributor

github-actions bot commented Feb 2, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

github-actions bot commented Feb 2, 2026

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 8,809 - 9,086 -3%
GET With Sentry 1,745 20% 1,653 +6%
GET With Sentry (error only) 6,280 71% 6,094 +3%
POST Baseline 1,218 - 1,166 +4%
POST With Sentry 594 49% 539 +10%
POST With Sentry (error only) 1,049 86% 1,027 +2%
MYSQL Baseline 3,392 - 3,282 +3%
MYSQL With Sentry 510 15% 393 +30%
MYSQL With Sentry (error only) 2,754 81% 2,680 +3%

View base workflow run

@RulaKhaled RulaKhaled marked this pull request as ready for review February 3, 2026 10:07
@RulaKhaled RulaKhaled marked this pull request as draft February 3, 2026 10:24
@RulaKhaled RulaKhaled force-pushed the fix-dependabot-alert branch from 099cd9f to 8596a4f Compare February 3, 2026 10:27
@RulaKhaled RulaKhaled changed the title fix(dependabot): force all tar dependencies to use the secure version fix(dependabot): Resolve tar vulnerability via yarn resolutions Feb 3, 2026
@RulaKhaled RulaKhaled closed this Feb 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(dependabot): force all tar dependencies to use the secure version

2 participants