Skip to content

fix(deps): bump brace-expansion to 1.1.21, 2.1.7 and 5.0.12 - #20

Merged
ashirman merged 1 commit into
mainfrom
fix/brace-expansion-dos
Oct 6, 2026
Merged

ashirman merged 1 commit into
mainfrom
fix/brace-expansion-dos

Conversation

@revopushbot

Copy link
Copy Markdown
Contributor

Summary

Fixes three brace-expansion denial-of-service advisories that affect the 1.x, 2.x and 5.x copies in our lockfiles:

Advisory Fixed in
GHSA-6j4f-fj2g-mc7p: unbounded recursion in parseCommaParts 1.1.19 / 2.1.5 / 5.0.10
GHSA-qhr7-859c-m2p7: unbounded recursion on nested brace groups 1.1.20 / 2.1.6 / 5.0.11
GHSA-q2hr-2g5m-vwhr: quadratic-time {a},b} expansion 1.1.21 / 2.1.7 / 5.0.12

This bumps 1.1.18 → 1.1.21, 2.1.4 → 2.1.7 and 5.0.9 → 5.0.12. All are transitive dev dependencies (via expo, glob, eslint and jest tooling). The patched releases are within the existing ^1.1.7, ^2.0.2 and ^5.0.5 ranges, so only the lockfiles change: no package.json edits and no overrides. The fixed releases have the same dependencies as the versions they replace.

Verification

  • yarn install --frozen-lockfile --ignore-scripts and npm ci --ignore-scripts succeed
  • yarn build passes
  • npm audit no longer reports brace-expansion

Other npm audit findings (braces, node-forge, source-map-js, compression, sprintf-js, etc.) are unrelated and not addressed here.

🤖 Generated with Claude Code

Resolves GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7 and
GHSA-q2hr-2g5m-vwhr (DoS). Lockfile-only: the fixed releases are
within the existing ^1.1.7, ^2.0.2 and ^5.0.5 ranges.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ashirman
ashirman merged commit 01af793 into main Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants