Skip to content

Conversation

@chargome
Copy link
Member

@chargome chargome commented Feb 7, 2026

Bump diff from 5.1.0 to 5.2.2 to address CVE-2026-24001 (DoS via unbounded memory allocation in parsePatch and applyPatch).

Bump diff from 5.1.0 to 5.2.2 to address CVE-2026-24001 (DoS via
unbounded memory allocation in parsePatch and applyPatch).

Co-Authored-By: Claude <noreply@anthropic.com>
@chargome chargome self-assigned this Feb 7, 2026
@github-actions
Copy link
Contributor

github-actions bot commented Feb 9, 2026

Codecov Results 📊


Generated by Codecov Action

@github-actions
Copy link
Contributor

github-actions bot commented Feb 9, 2026

size-limit report 📦

Path Size % Change Change
@sentry/browser 25.54 kB +0.02% +3 B 🔺
@sentry/browser - with treeshaking flags 24 kB -0.21% -49 B 🔽
@sentry/browser (incl. Tracing) 42.37 kB +0.04% +15 B 🔺
@sentry/browser (incl. Tracing, Profiling) 47.02 kB +0.01% +4 B 🔺
@sentry/browser (incl. Tracing, Replay) 81.01 kB +0.01% +6 B 🔺
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 70.61 kB -0.06% -36 B 🔽
@sentry/browser (incl. Tracing, Replay with Canvas) 85.71 kB +0.01% +3 B 🔺
@sentry/browser (incl. Tracing, Replay, Feedback) 97.89 kB -0.02% -10 B 🔽
@sentry/browser (incl. Feedback) 42.26 kB -0.02% -8 B 🔽
@sentry/browser (incl. sendFeedback) 30.22 kB - -
@sentry/browser (incl. FeedbackAsync) 35.23 kB +0.06% +21 B 🔺
@sentry/browser (incl. Metrics) 26.65 kB -0.25% -65 B 🔽
@sentry/browser (incl. Logs) 26.79 kB -0.22% -58 B 🔽
@sentry/browser (incl. Metrics & Logs) 27.47 kB -0.23% -61 B 🔽
@sentry/react 27.25 kB -0.2% -52 B 🔽
@sentry/react (incl. Tracing) 44.63 kB -0.11% -48 B 🔽
@sentry/vue 29.98 kB -0.03% -7 B 🔽
@sentry/vue (incl. Tracing) 44.21 kB +0.02% +7 B 🔺
@sentry/svelte 25.55 kB -0.03% -6 B 🔽
CDN Bundle 28.08 kB - -
CDN Bundle (incl. Tracing) 43.15 kB - -
CDN Bundle (incl. Logs, Metrics) 28.92 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 43.99 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 67.86 kB - -
CDN Bundle (incl. Tracing, Replay) 79.91 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 80.77 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 85.33 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 86.23 kB - -
CDN Bundle - uncompressed 82.12 kB - -
CDN Bundle (incl. Tracing) - uncompressed 127.83 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 84.95 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 130.66 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 208.33 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 244.43 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 247.25 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 257.23 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 260.04 kB - -
@sentry/nextjs (client) 46.97 kB -0.1% -43 B 🔽
@sentry/sveltekit (client) 42.77 kB -0.04% -16 B 🔽
@sentry/node-core 52.18 kB -0.03% -12 B 🔽
@sentry/node 166.3 kB -0.02% -21 B 🔽
@sentry/node - without tracing 93.97 kB -0.01% -6 B 🔽
@sentry/aws-serverless 109.48 kB +0.02% +13 B 🔺

View base workflow run

@github-actions
Copy link
Contributor

github-actions bot commented Feb 9, 2026

node-overhead report 🧳

Note: This is a synthetic benchmark with a minimal express app and does not necessarily reflect the real-world performance impact in an application.

Scenario Requests/s % of Baseline Prev. Requests/s Change %
GET Baseline 8,599 - 9,436 -9%
GET With Sentry 1,624 19% 1,705 -5%
GET With Sentry (error only) 6,014 70% 6,238 -4%
POST Baseline 1,184 - 1,209 -2%
POST With Sentry 568 48% 591 -4%
POST With Sentry (error only) 1,056 89% 1,039 +2%
MYSQL Baseline 3,305 - 3,339 -1%
MYSQL With Sentry 492 15% 483 +2%
MYSQL With Sentry (error only) 2,662 81% 2,700 -1%

View base workflow run

@chargome chargome requested a review from andreiborza February 9, 2026 16:29
@chargome chargome enabled auto-merge (squash) February 9, 2026 16:29
@chargome chargome merged commit 75e0bb6 into develop Feb 10, 2026
448 of 452 checks passed
@chargome chargome deleted the fix/bump-diff-5.2.2 branch February 10, 2026 08:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants