Skip to content

Bump brace-expansion from 1.1.11 to 1.1.12#8440

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/brace-expansion-1.1.12
Open

Bump brace-expansion from 1.1.11 to 1.1.12#8440
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/npm_and_yarn/brace-expansion-1.1.12

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Feb 18, 2026

Bumps brace-expansion from 1.1.11 to 1.1.12.

Release notes

Sourced from brace-expansion's releases.

v1.1.12

  • pkg: publish on tag 1.x c460dbd
  • fmt ccb8ac6
  • Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8

juliangruber/brace-expansion@v1.1.11...v1.1.12

Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Feb 18, 2026
@cursor
Copy link
Copy Markdown

cursor bot commented Feb 18, 2026

PR Summary

Low Risk
Low risk lockfile-only change updating a transitive dependency; potential impact is limited to dependency resolution/runtime behavior of packages that rely on brace-expansion.

Overview
Updates the Yarn lockfile to resolve brace-expansion@^1.1.7 to 1.1.13 (including updated integrity checksum), with no application code changes.

Written by Cursor Bugbot for commit a0e7469. This will update automatically on new commits. Configure here.

@vercel
Copy link
Copy Markdown

vercel bot commented Feb 18, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hash Ready Ready Preview, Comment Apr 1, 2026 4:02pm
hashdotdesign Ready Ready Preview, Comment Apr 1, 2026 4:02pm
hashdotdesign-tokens Ready Ready Preview, Comment Apr 1, 2026 4:02pm
petrinaut Ready Ready Preview Apr 1, 2026 4:02pm

@github-actions github-actions bot added the area/deps Relates to third-party dependencies (area) label Feb 18, 2026
@augmentcode
Copy link
Copy Markdown

augmentcode bot commented Feb 18, 2026

🤖 Augment PR Summary

Summary: Updates the Yarn lockfile to bump brace-expansion from 1.1.11 to 1.1.12.

Why: Pulls in the upstream patch release, including a fix for a potential ReDoS/inefficient regex issue.

🤖 Was this summary useful? React with 👍 or 👎

Copy link
Copy Markdown

@augmentcode augmentcode bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review completed. No suggestions at this time.

Comment augment review to trigger a new review at any time.

CiaranMn
CiaranMn previously approved these changes Feb 18, 2026
@codspeed-hq
Copy link
Copy Markdown

codspeed-hq bot commented Feb 18, 2026

Merging this PR will not alter performance

✅ 80 untouched benchmarks


Comparing dependabot/npm_and_yarn/brace-expansion-1.1.12 (a0e7469) with main (0c2347e)1

Open in CodSpeed

Footnotes

  1. No successful run was found on main (8fe5479) during the generation of this report, so 0c2347e was used instead as the comparison base. There might be some changes unrelated to this pull request in this report.

@github-actions
Copy link
Copy Markdown
Contributor

Benchmark results

@rust/hash-graph-benches – Integrations

policy_resolution_large

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2002 $$28.4 \mathrm{ms} \pm 182 \mathrm{μs}\left({\color{lightgreen}-6.370 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.63 \mathrm{ms} \pm 18.1 \mathrm{μs}\left({\color{gray}-1.096 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 1001 $$14.1 \mathrm{ms} \pm 74.4 \mathrm{μs}\left({\color{gray}-4.841 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 3314 $$46.2 \mathrm{ms} \pm 394 \mathrm{μs}\left({\color{gray}1.27 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$16.2 \mathrm{ms} \pm 147 \mathrm{μs}\left({\color{gray}0.669 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 1526 $$25.8 \mathrm{ms} \pm 217 \mathrm{μs}\left({\color{gray}-2.926 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 2078 $$29.6 \mathrm{ms} \pm 178 \mathrm{μs}\left({\color{gray}-3.866 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.92 \mathrm{ms} \pm 21.4 \mathrm{μs}\left({\color{gray}-3.194 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 1033 $$14.8 \mathrm{ms} \pm 102 \mathrm{μs}\left({\color{lightgreen}-5.246 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_medium

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 102 $$4.05 \mathrm{ms} \pm 25.8 \mathrm{μs}\left({\color{gray}0.258 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.22 \mathrm{ms} \pm 16.7 \mathrm{μs}\left({\color{gray}0.340 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 51 $$3.63 \mathrm{ms} \pm 20.6 \mathrm{μs}\left({\color{gray}0.400 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 269 $$5.56 \mathrm{ms} \pm 32.1 \mathrm{μs}\left({\color{gray}-3.255 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$3.79 \mathrm{ms} \pm 18.1 \mathrm{μs}\left({\color{gray}-2.861 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 107 $$4.44 \mathrm{ms} \pm 30.0 \mathrm{μs}\left({\color{gray}-2.658 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 133 $$4.82 \mathrm{ms} \pm 41.6 \mathrm{μs}\left({\color{gray}1.05 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.70 \mathrm{ms} \pm 19.8 \mathrm{μs}\left({\color{gray}-1.075 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 63 $$4.37 \mathrm{ms} \pm 42.2 \mathrm{μs}\left({\color{gray}-1.711 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_none

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 2 $$2.94 \mathrm{ms} \pm 26.0 \mathrm{μs}\left({\color{gray}0.677 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$2.85 \mathrm{ms} \pm 19.5 \mathrm{μs}\left({\color{gray}-1.420 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 1 $$3.00 \mathrm{ms} \pm 17.9 \mathrm{μs}\left({\color{gray}0.848 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 8 $$3.29 \mathrm{ms} \pm 20.9 \mathrm{μs}\left({\color{gray}0.831 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.07 \mathrm{ms} \pm 19.8 \mathrm{μs}\left({\color{gray}-0.229 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 3 $$3.36 \mathrm{ms} \pm 21.8 \mathrm{μs}\left({\color{gray}-1.656 \mathrm{\%}}\right) $$ Flame Graph

policy_resolution_small

Function Value Mean Flame graphs
resolve_policies_for_actor user: empty, selectivity: high, policies: 52 $$3.32 \mathrm{ms} \pm 19.4 \mathrm{μs}\left({\color{gray}-0.351 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: low, policies: 1 $$3.01 \mathrm{ms} \pm 15.8 \mathrm{μs}\left({\color{gray}0.007 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: empty, selectivity: medium, policies: 25 $$3.18 \mathrm{ms} \pm 17.3 \mathrm{μs}\left({\color{gray}1.11 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: high, policies: 94 $$3.73 \mathrm{ms} \pm 16.7 \mathrm{μs}\left({\color{gray}-1.234 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: low, policies: 1 $$3.31 \mathrm{ms} \pm 15.1 \mathrm{μs}\left({\color{gray}-1.312 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: seeded, selectivity: medium, policies: 26 $$3.51 \mathrm{ms} \pm 17.1 \mathrm{μs}\left({\color{gray}-4.081 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: high, policies: 66 $$3.64 \mathrm{ms} \pm 21.5 \mathrm{μs}\left({\color{gray}-2.108 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: low, policies: 1 $$3.28 \mathrm{ms} \pm 19.0 \mathrm{μs}\left({\color{gray}-0.793 \mathrm{\%}}\right) $$ Flame Graph
resolve_policies_for_actor user: system, selectivity: medium, policies: 29 $$3.56 \mathrm{ms} \pm 17.9 \mathrm{μs}\left({\color{gray}0.292 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_complete

Function Value Mean Flame graphs
entity_by_id;one_depth 1 entities $$43.9 \mathrm{ms} \pm 252 \mathrm{μs}\left({\color{gray}-0.589 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 10 entities $$80.9 \mathrm{ms} \pm 692 \mathrm{μs}\left({\color{gray}-0.571 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 25 entities $$48.1 \mathrm{ms} \pm 270 \mathrm{μs}\left({\color{gray}-2.506 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 5 entities $$51.2 \mathrm{ms} \pm 527 \mathrm{μs}\left({\color{gray}1.79 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;one_depth 50 entities $$59.5 \mathrm{ms} \pm 482 \mathrm{μs}\left({\color{gray}-1.415 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 1 entities $$44.5 \mathrm{ms} \pm 229 \mathrm{μs}\left({\color{gray}-1.828 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 10 entities $$421 \mathrm{ms} \pm 1.15 \mathrm{ms}\left({\color{gray}0.852 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 25 entities $$101 \mathrm{ms} \pm 490 \mathrm{μs}\left({\color{gray}-1.405 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 5 entities $$90.1 \mathrm{ms} \pm 391 \mathrm{μs}\left({\color{gray}0.254 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;two_depth 50 entities $$325 \mathrm{ms} \pm 1.08 \mathrm{ms}\left({\color{red}10.4 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 1 entities $$16.5 \mathrm{ms} \pm 117 \mathrm{μs}\left({\color{gray}-0.230 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 10 entities $$16.7 \mathrm{ms} \pm 78.9 \mathrm{μs}\left({\color{gray}-1.673 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 25 entities $$17.2 \mathrm{ms} \pm 109 \mathrm{μs}\left({\color{gray}0.835 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 5 entities $$16.7 \mathrm{ms} \pm 87.7 \mathrm{μs}\left({\color{gray}-1.058 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id;zero_depth 50 entities $$20.0 \mathrm{ms} \pm 113 \mathrm{μs}\left({\color{gray}0.009 \mathrm{\%}}\right) $$ Flame Graph

read_scaling_linkless

Function Value Mean Flame graphs
entity_by_id 1 entities $$16.6 \mathrm{ms} \pm 79.7 \mathrm{μs}\left({\color{gray}-2.090 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10 entities $$16.5 \mathrm{ms} \pm 96.2 \mathrm{μs}\left({\color{gray}-2.018 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 100 entities $$16.5 \mathrm{ms} \pm 97.8 \mathrm{μs}\left({\color{gray}-1.628 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 1000 entities $$17.1 \mathrm{ms} \pm 85.6 \mathrm{μs}\left({\color{gray}-2.109 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id 10000 entities $$25.6 \mathrm{ms} \pm 234 \mathrm{μs}\left({\color{gray}-0.611 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity

Function Value Mean Flame graphs
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/block/v/1 $$32.0 \mathrm{ms} \pm 298 \mathrm{μs}\left({\color{gray}-1.630 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/book/v/1 $$32.1 \mathrm{ms} \pm 339 \mathrm{μs}\left({\color{gray}-2.743 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/building/v/1 $$32.0 \mathrm{ms} \pm 254 \mathrm{μs}\left({\color{lightgreen}-6.272 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/organization/v/1 $$32.1 \mathrm{ms} \pm 276 \mathrm{μs}\left({\color{gray}-1.301 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/page/v/2 $$33.3 \mathrm{ms} \pm 315 \mathrm{μs}\left({\color{gray}-1.128 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/person/v/1 $$32.8 \mathrm{ms} \pm 283 \mathrm{μs}\left({\color{gray}-3.617 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/playlist/v/1 $$32.7 \mathrm{ms} \pm 300 \mathrm{μs}\left({\color{gray}-0.178 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/song/v/1 $$32.0 \mathrm{ms} \pm 344 \mathrm{μs}\left({\color{gray}-4.719 \mathrm{\%}}\right) $$ Flame Graph
entity_by_id entity type ID: https://blockprotocol.org/@alice/types/entity-type/uk-address/v/1 $$32.4 \mathrm{ms} \pm 284 \mathrm{μs}\left({\color{gray}-3.849 \mathrm{\%}}\right) $$ Flame Graph

representative_read_entity_type

Function Value Mean Flame graphs
get_entity_type_by_id Account ID: bf5a9ef5-dc3b-43cf-a291-6210c0321eba $$9.23 \mathrm{ms} \pm 53.4 \mathrm{μs}\left({\color{gray}0.022 \mathrm{\%}}\right) $$ Flame Graph

representative_read_multiple_entities

Function Value Mean Flame graphs
entity_by_property traversal_paths=0 0 $$95.5 \mathrm{ms} \pm 548 \mathrm{μs}\left({\color{gray}-2.388 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$152 \mathrm{ms} \pm 589 \mathrm{μs}\left({\color{gray}-1.169 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$104 \mathrm{ms} \pm 511 \mathrm{μs}\left({\color{gray}-2.437 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$113 \mathrm{ms} \pm 558 \mathrm{μs}\left({\color{gray}0.939 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$123 \mathrm{ms} \pm 524 \mathrm{μs}\left({\color{gray}0.039 \mathrm{\%}}\right) $$
entity_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$129 \mathrm{ms} \pm 655 \mathrm{μs}\left({\color{gray}-0.228 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=0 0 $$91.1 \mathrm{ms} \pm 462 \mathrm{μs}\left({\color{gray}-1.589 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=255 1,resolve_depths=inherit:1;values:255;properties:255;links:127;link_dests:126;type:true $$122 \mathrm{ms} \pm 476 \mathrm{μs}\left({\color{gray}-0.189 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:0;link_dests:0;type:false $$99.9 \mathrm{ms} \pm 575 \mathrm{μs}\left({\color{gray}-0.475 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:0;links:1;link_dests:0;type:true $$107 \mathrm{ms} \pm 477 \mathrm{μs}\left({\color{gray}0.339 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:0;properties:2;links:1;link_dests:0;type:true $$110 \mathrm{ms} \pm 510 \mathrm{μs}\left({\color{gray}-1.444 \mathrm{\%}}\right) $$
link_by_source_by_property traversal_paths=2 1,resolve_depths=inherit:0;values:2;properties:2;links:1;link_dests:0;type:true $$112 \mathrm{ms} \pm 543 \mathrm{μs}\left({\color{gray}0.068 \mathrm{\%}}\right) $$

scenarios

Function Value Mean Flame graphs
full_test query-limited $$139 \mathrm{ms} \pm 533 \mathrm{μs}\left({\color{gray}3.26 \mathrm{\%}}\right) $$ Flame Graph
full_test query-unlimited $$138 \mathrm{ms} \pm 624 \mathrm{μs}\left({\color{gray}4.76 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-limited $$107 \mathrm{ms} \pm 555 \mathrm{μs}\left({\color{gray}0.159 \mathrm{\%}}\right) $$ Flame Graph
linked_queries query-unlimited $$602 \mathrm{ms} \pm 1.31 \mathrm{ms}\left({\color{gray}1.02 \mathrm{\%}}\right) $$ Flame Graph

@github-actions github-actions bot dismissed CiaranMn’s stale review April 1, 2026 15:43

Could not find data on the previous version of this PR; see action logs at https://github.com/hashintel/hash/actions/runs/23857274072

@CiaranMn CiaranMn disabled auto-merge April 1, 2026 15:43
@CiaranMn
Copy link
Copy Markdown
Member

CiaranMn commented Apr 1, 2026

@dependabot recreate

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.11 to 1.1.12.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.12
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/deps Relates to third-party dependencies (area) dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Development

Successfully merging this pull request may close these issues.

1 participant