Skip to content

Override brace-expansion to 2.1.4 - #38

Closed
eschultink wants to merge 1 commit into
mainfrom
s232-brace-expansion
Closed

Override brace-expansion to 2.1.4#38
eschultink wants to merge 1 commit into
mainfrom
s232-brace-expansion

Conversation

@eschultink

Copy link
Copy Markdown
Member

Summary

  • Dependabot alert #49 is still open: brace-expansion 2.1.0 via minimatch is vulnerable to CVE-2026-14257 (and the 2.1.3 bypass GHSA-rgw5-rvv9-x895).
  • Pin the transitive package to 2.1.4 with an npm override so it stays patched.

Fixes

Supersedes Dependabot PR #37 (same bump, plus an override).

Features

n/a

Change implications

  • includes or requires infrastructure changes? (tag 'infra-change') no

Made with Cursor

2.1.0 is still in the lockfile via minimatch; 2.1.4 patches CVE-2026-14257 and the follow-on GHSA-rgw5-rvv9-x895 bypass.

Co-authored-by: Cursor <cursoragent@cursor.com>
@eschultink eschultink self-assigned this Aug 27, 2026
@eschultink
eschultink requested a review from jlorper August 27, 2026 04:33

@claude claude Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

Claude Code Review is paused for this repository. To reconnect it, an admin of this repository's GitHub organization (or the account owner, for personal repositories) who can also manage your Claude organization's Code Review settings needs to re-link GitHub in Code Review settings. This is a one-time step.

Tip: disable this comment in your organization's Code Review settings.

@eschultink eschultink closed this Aug 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant