Skip to content

chore: Bump brace-expansion from 5.0.6 to 5.0.8 - #193

Open
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-5.0.8
Open

chore: Bump brace-expansion from 5.0.6 to 5.0.8#193
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-5.0.8

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps brace-expansion from 5.0.6 to 5.0.8 to address a Regular Expression Denial of Service (ReDoS) vulnerability.

Lockfile-only change (transitive dependency; package-lock.json only). Only the node_modules/minimatch/node_modules/brace-expansion (v5 line) entry changes.

  • Advisory: GHSA-3jxr-9vmj-r5cp (High)
  • Vulnerable versions: >= 3.0.0, < 5.0.7Patched version: 5.0.7 (bumped to latest 5.0.8)

Note: the v2 line (brace-expansion 2.0.3 → 2.1.2) is already covered by the open Dependabot PR #192, so it is intentionally left untouched here.

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate a Dependabot alert that had no auto-generated fix.

@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 11:58
@ernst-dev
ernst-dev requested review from taheramr and removed request for a team July 23, 2026 11:58
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@codecov

codecov Bot commented Jul 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 97.11%. Comparing base (c2dae6a) to head (1b3f3b1).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #193   +/-   ##
=======================================
  Coverage   97.11%   97.11%           
=======================================
  Files          55       55           
  Lines        1420     1420           
  Branches      251      251           
=======================================
  Hits         1379     1379           
  Misses         35       35           
  Partials        6        6           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ernst-dev
ernst-dev requested review from SpyZzey and removed request for taheramr July 29, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant