Skip to content

chore: Bump brace-expansion to 1.1.16 and 2.1.2 - #241

Open
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-multi
Open

chore: Bump brace-expansion to 1.1.16 and 2.1.2#241
ernst-dev wants to merge 2 commits into
mainfrom
dependabot/npm_and_yarn/brace-expansion-multi

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps brace-expansion to patched versions to address a Regular Expression Denial of Service (ReDoS) vulnerability (GHSA-3jxr-9vmj-r5cp, High).

Lockfile-only change (transitive dependency; package-lock.json only). Both vulnerable major-version lines present in the tree are bumped:

Line From To Vulnerable range
v1 (brace-expansion) 1.1.15 1.1.16 < 1.1.16
v2 (glob, readdir-globbrace-expansion) 2.1.1 2.1.2 >= 2.0.0, < 2.1.2

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate Dependabot alerts that had no auto-generated fix.

@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 11:35
@ernst-dev
ernst-dev requested review from taheramr and removed request for a team July 23, 2026 11:35
@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@codecov

codecov Bot commented Jul 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.06%. Comparing base (0ff0098) to head (ac107da).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #241   +/-   ##
=======================================
  Coverage   93.06%   93.06%           
=======================================
  Files          20       20           
  Lines         476      476           
  Branches       84       84           
=======================================
  Hits          443      443           
  Misses         29       29           
  Partials        4        4           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ernst-dev
ernst-dev requested review from SpyZzey and removed request for taheramr July 29, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant