Skip to content

chore: Bump brace-expansion to 1.1.16, 2.1.2 and 5.0.8 - #65

Open
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-multi
Open

chore: Bump brace-expansion to 1.1.16, 2.1.2 and 5.0.8#65
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-multi

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps brace-expansion to patched versions to address a Regular Expression Denial of Service (ReDoS) vulnerability (GHSA-3jxr-9vmj-r5cp, High).

Lockfile-only change (transitive dependency; package-lock.json only). All three vulnerable major-version lines present in the tree are bumped:

Line From To Vulnerable range
v1 (brace-expansion) 1.1.13 1.1.16 < 1.1.16
v2 (@typescript-eslint/typescript-estreebrace-expansion) 2.0.3 2.1.2 >= 2.0.0, < 2.1.2
v5 (minimatchbrace-expansion) 5.0.6 5.0.8 >= 3.0.0, < 5.0.7 (patched 5.0.7)
  • Advisory: GHSA-3jxr-9vmj-r5cp
  • Patched versions: 1.1.16, 2.1.2, 5.0.7 (v5 bumped to latest 5.0.8)

Dependency sets are unchanged; only brace-expansion entries change.

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate Dependabot alerts that had no auto-generated fix.

@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 12:01
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested review from srungta08 and removed request for a team July 23, 2026 12:01
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested review from SpyZzey and removed request for srungta08 July 29, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant