Skip to content

fix(deps): bump transitive brace-expansion to 2.1.7 and 1.1.21 - #20

Merged
ashirman merged 1 commit into
masterfrom
fix/brace-expansion
Oct 6, 2026
Merged

ashirman merged 1 commit into
masterfrom
fix/brace-expansion

Conversation

@revopushbot

Copy link
Copy Markdown
Collaborator

Summary

Fixes the Dependabot alerts on brace-expansion. The lockfile has two copies, and both are affected:

Copy Pulled in by Range Before → After
2.x minimatch@9 ^2.0.2 2.1.4 → 2.1.7
1.x shelljs → minimatch@3 ^1.1.7 1.1.18 → 1.1.21

Advisories fixed: GHSA-6j4f-fj2g-mc7p (high), GHSA-qhr7-859c-m2p7 (high), GHSA-q2hr-2g5m-vwhr (moderate).

Both fixed versions are already within their parents' ranges, so this only changes package-lock.json (npm update brace-expansion). package.json is untouched.

Test plan

  • npm audit: 0 vulnerabilities
  • npm run build:release passes
  • npm test: 57 passing, 1 failing. The failure is the existing Acquisition SDK › disables api calls on unsuccessful response, which also fails on master.

🤖 Generated with Claude Code

Fixes GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and GHSA-q2hr-2g5m-vwhr.
Lockfile-only: minimatch@9 (^2.0.2) and shelljs's minimatch@3 (^1.1.7)
already allow the fixed versions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ashirman
ashirman merged commit ea3d59b into master Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants