Skip to content

Bump brace-expansion to 1.1.21 (GHSA-q2hr-2g5m-vwhr) - #7287

Open
jencarlucci wants to merge 1 commit into
mainfrom
security/bump-deps-vuln-267586
Open

jencarlucci wants to merge 1 commit into
mainfrom
security/bump-deps-vuln-267586

Conversation

@jencarlucci

Copy link
Copy Markdown
Contributor

Remediates the Dependabot finding tracked in github/vuln-mgmt.

Findings addressed

Dependency From To Severity Scope Vulnerability Advisory
brace-expansion 1.1.16 1.1.21 🟡 Medium development Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service (CVE-2026-102277) GHSA-q2hr-2g5m-vwhr

What changed

brace-expansion is a dev-only transitive dependency, pulled in via eslint. It is not declared directly, so it is pinned through the existing overrides block (already used here for lodash and js-yaml).

Added "brace-expansion": ">=1.1.21 <2", which requires the patched release while staying inside the 1.x line — no major version bump.

package-lock.json was regenerated with npm install --package-lock-only. The diff touches only brace-expansion; all resolved URLs remain on registry.npmjs.org.

Because the dependency is development-scoped, there is no runtime exposure in the published descriptions — this only affects linting in CI.

Related: https://github.com/github/vuln-mgmt/issues/267586

Opened by the API Platform FR runbook (security-finding-remediator).

brace-expansion is a dev-only transitive dependency (via eslint).
Add an explicit override floor of >=1.1.21 <2 so the patched release
is required, staying inside the 1.x line.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7a2507e5-5868-45bf-aa18-07670377dbb1
Copilot AI balanced review requested due to automatic review settings October 7, 2026 17:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The override and lockfile consistently apply the documented patched version without runtime dependency changes.

0 open findings

What changed in this PR

Pins the dev-only brace-expansion dependency to a patched 1.x release addressing GHSA-q2hr-2g5m-vwhr.

Changes:

  • Adds an npm override requiring brace-expansion 1.1.21 or later within 1.x.
  • Regenerates the lockfile with version 1.1.21 and matching metadata.
File Description
package.json Adds the secure dependency override.
package-lock.json Locks brace-expansion to 1.1.21.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants