Repository navigation
chore(deps): bump brace-expansion from 1.1.16 to 5.0.12 - #67
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.16 to 5.0.12. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.16...v5.0.12) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.12 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 54af32e. Configure here.
| minimatch@9.0.9: | ||
| dependencies: | ||
| brace-expansion: 2.1.2 | ||
| brace-expansion: 5.0.12 |
There was a problem hiding this comment.
Incompatible brace-expansion version forced
High Severity
The lockfile remaps minimatch@3.1.5 and minimatch@9.0.9 onto brace-expansion@5.0.12. Those minimatch releases call the package as a default function, but v5 only exposes a named expand export, so eslint and glob throw TypeError on brace patterns.
Additional Locations (1)
Reviewed by Cursor Bugbot for commit 54af32e. Configure here.


Bumps brace-expansion from 1.1.16 to 5.0.12.
Release notes
Sourced from brace-expansion's releases.
... (truncated)
Commits
f3410155.0.1233a5ef1Merge commit from fork82479275.0.11935d78fMerge commit from forkdf7682f5.0.101ade9denpm run format6735c94Merge commit from fork4e70465chore: ensure prettier formatting (#154)fd7a5e3Bump ip-address from 10.2.0 to 10.4.0 (#152)1790143Bump uuid and@tapjs/processinfo(#120)Install script changes
This version adds
preparescript that runs during installation. Review the package contents before updating.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Lockfile-only transitive dependency bump with no application source changes; main caveat is stricter Node engine on brace-expansion 5.x and a major-version jump in a glob-related helper used by minimatch.
Overview
Updates
pnpm-lock.yamlso everyminimatchresolution (v3, v9, and v10) pullsbrace-expansion@5.0.12instead of the older 1.x, 2.x, and 5.0.5 copies that were pinned separately.That consolidation drops legacy lockfile entries for
balanced-match@1.0.2andconcat-maptied to the old brace-expansion tree;brace-expansion@5.0.12now depends onbalanced-match@4.0.4. The lockfile also recordseslint@9.39.4as deprecated (likely from the same refresh, not an app code change).This is a Dependabot security/maintenance bump (including ReDoS fixes noted in brace-expansion release history).
brace-expansion@5.0.12requires Node 20 or ≥22, which matters only if install/runtime environments are older.Reviewed by Cursor Bugbot for commit 54af32e. Bugbot is set up for automated code reviews on this repo. Configure here.