Skip to content

Bump brace-expansion from 1.1.11 to 1.1.18 - #6135

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/brace-expansion-1.1.18
Open

Bump brace-expansion from 1.1.11 to 1.1.18#6135
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/npm_and_yarn/brace-expansion-1.1.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.11 to 1.1.18.

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

v1.1.12

  • pkg: publish on tag 1.x c460dbd
  • fmt ccb8ac6
  • Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8

juliangruber/brace-expansion@v1.1.11...v1.1.12

Commits


Note

Low Risk
Lockfile-only transitive dependency updates with no app code changes; low risk and intended to reduce known brace-expansion vulnerability exposure.

Overview
Updates package-lock.json only: the root brace-expansion entry moves from 1.1.11 to 1.1.18, and several nested copies (under Expo CLI, fingerprint, metro-config, TypeScript ESLint, eslint-plugin-n, and glob) move from 2.0.1 to 2.1.4, with resolved URLs and integrity hashes added where missing.

There are no application source changes; this is a dependency lockfile refresh for a transitive package used by glob/minimatch-style tooling. The upstream release notes cite ReDoS fixes and security backports (e.g. GHSA-mh99-v99m-4gvg, CVE-2026-13149) on the 1.x line.

Reviewed by Cursor Bugbot for commit e476f3c. Bugbot is set up for automated code reviews on this repo. Configure here.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 3, 2026
@dependabot dependabot Bot mentioned this pull request Aug 3, 2026
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.11 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.18)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/brace-expansion-1.1.18 branch from bfff9c9 to e476f3c Compare August 3, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants