Repository navigation
Bump brace-expansion to 1.1.21 (GHSA-q2hr-2g5m-vwhr) - #7287
Open
jencarlucci wants to merge 1 commit into
Open
jencarlucci wants to merge 1 commit into
jencarlucci wants to merge 1 commit into
Conversation
brace-expansion is a dev-only transitive dependency (via eslint). Add an explicit override floor of >=1.1.21 <2 so the patched release is required, staying inside the 1.x line. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7a2507e5-5868-45bf-aa18-07670377dbb1
Contributor
There was a problem hiding this comment.
🟢 Approval recommended
The override and lockfile consistently apply the documented patched version without runtime dependency changes.
0 open findings
What changed in this PR
Pins the dev-only brace-expansion dependency to a patched 1.x release addressing GHSA-q2hr-2g5m-vwhr.
Changes:
- Adds an npm override requiring
brace-expansion1.1.21 or later within 1.x. - Regenerates the lockfile with version 1.1.21 and matching metadata.
| File | Description |
|---|---|
package.json |
Adds the secure dependency override. |
package-lock.json |
Locks brace-expansion to 1.1.21. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
shawnHartsell
approved these changes
Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remediates the Dependabot finding tracked in github/vuln-mgmt.
Findings addressed
brace-expansion{a},b}rewrite causes CPU denial of service (CVE-2026-102277)What changed
brace-expansionis a dev-only transitive dependency, pulled in viaeslint. It is not declared directly, so it is pinned through the existingoverridesblock (already used here forlodashandjs-yaml).Added
"brace-expansion": ">=1.1.21 <2", which requires the patched release while staying inside the 1.x line — no major version bump.package-lock.jsonwas regenerated withnpm install --package-lock-only. The diff touches onlybrace-expansion; allresolvedURLs remain onregistry.npmjs.org.Because the dependency is development-scoped, there is no runtime exposure in the published descriptions — this only affects linting in CI.
Related: https://github.com/github/vuln-mgmt/issues/267586
Opened by the API Platform FR runbook (
security-finding-remediator).