Skip to content

[Security] UID2-7576/7577/7578: Upgrade brace-expansion 5.0.8 + postcss 8.5.18 - #203

Merged
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7576-npm-sec
Jul 27, 2026
Merged

[Security] UID2-7576/7577/7578: Upgrade brace-expansion 5.0.8 + postcss 8.5.18#203
cYKatherine merged 1 commit into
mainfrom
kchen-UID2-7576-npm-sec

Conversation

@cYKatherine

Copy link
Copy Markdown
Contributor

Summary

Resolves HIGH-severity npm dependency vulnerabilities flagged by the scheduled Trivy scan across the web-integrations/* example projects.

Package CVE / GHSA Fix Sub-projects
brace-expansion CVE-2026-14257 (ReDoS) brace-expansion@5 override 5.0.75.0.8 all 7 flagged
postcss CVE-2026-45623 (arbitrary file read), GHSA-r28c-9q8g-f849 (path traversal) postcss override → 8.5.18 google-secure-signals & javascript-sdk react-client-side

Build/tooling transitive deps; drop-in fixed versions exist → upgrade rather than suppress. All affected package-lock.json files regenerated (brace-expansion → 5.0.8, postcss → 8.5.18).

Tickets

UID2-7576 (brace-expansion); UID2-7577, UID2-7578 (postcss)

Testing

Builds run in CI.

Resolves HIGH-severity npm vulnerabilities flagged by the Trivy scan across the
web-integrations example sub-projects:
- brace-expansion: CVE-2026-14257 (ReDoS). override pin brace-expansion@5
  5.0.7 -> 5.0.8 (all 7 sub-projects).
- postcss: CVE-2026-45623, GHSA-r28c-9q8g-f849. override 8.5.18 in the two
  react-client-side sub-projects.
Lockfiles regenerated.

UID2-7576 UID2-7577 UID2-7578

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
swibi-ttd
swibi-ttd previously approved these changes Jul 27, 2026
@swibi-ttd
swibi-ttd dismissed their stale review July 27, 2026 06:54

Withdrawn

@cYKatherine
cYKatherine merged commit d21d8c4 into main Jul 27, 2026
3 checks passed
@cYKatherine
cYKatherine deleted the kchen-UID2-7576-npm-sec branch July 27, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants