Skip to content

fix(deps): patch brace-expansion denial-of-service vulnerabilities - #2

Merged
bensitu merged 1 commit into
masterfrom
codex/fix-brace-expansion
Sep 30, 2026
Merged

bensitu merged 1 commit into
masterfrom
codex/fix-brace-expansion

Conversation

@bensitu

@bensitu bensitu commented Sep 30, 2026

Copy link
Copy Markdown
Owner

The development dependency chain ESLint → minimatch locks brace-expansion 5.0.9, which is affected by denial-of-service advisories GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, and GHSA-q2hr-2g5m-vwhr.

Update only brace-expansion to 5.0.12 in package-lock.json. This patch satisfies minimatch's existing ^5.0.8 dependency range and the project's full Node.js engine range; no manifest override or direct dependency change is needed.

Validation on Node.js 24.16.0:

  • npm ci --engine-strict and npm audit: zero vulnerabilities.
  • Formatting, ESLint, build, and git diff --check passed.
  • 107 unit tests and coverage thresholds passed.
  • 16 Chromium end-to-end tests passed.
  • Confirmed only one package entry changed in the lockfile.

@bensitu
bensitu merged commit 45082ce into master Sep 30, 2026
4 checks passed
@bensitu
bensitu deleted the codex/fix-brace-expansion branch September 30, 2026 16:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant