Skip to content

chore: patch brace-expansion vulnerabilities - #247

Open
thomasnormal wants to merge 1 commit into
mainfrom
chore/patch-brace-expansion-security-20260830
Open

chore: patch brace-expansion vulnerabilities#247
thomasnormal wants to merge 1 commit into
mainfrom
chore/patch-brace-expansion-security-20260830

Conversation

@thomasnormal

Copy link
Copy Markdown
Member

Summary

  • update transitive brace-expansion 1.x from 1.1.11 to 1.1.18
  • update transitive brace-expansion 2.x from 2.0.1 to 2.1.4
  • keep the change lockfile-only and avoid unrelated resolver churn

Fixes the active Dependabot alert for brace-expansion < 1.1.18 and removes the known 2.x advisories reported by pnpm audit.

Validation

  • corepack pnpm install --lockfile-only --frozen-lockfile
  • corepack pnpm audit --json reports zero brace-expansion advisories
  • git diff --check

Note: the repository still has unrelated pre-existing audit findings.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for your contribution. We will check and reply to you as soon as possible.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants