Skip to content

Relock brace-expansion past new advisories - #92

Merged
vvillait88 merged 1 commit into
mainfrom
chore/advisory-relock-2026-09-29
Sep 30, 2026
Merged

vvillait88 merged 1 commit into
mainfrom
chore/advisory-relock-2026-09-29

Conversation

@vvillait88

Copy link
Copy Markdown
Contributor

Summary

Relocks brace-expansion from 1.1.18 to 1.1.21 and from 5.0.9 to 5.0.12, past three advisories published 2026-09-29 (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr; two HIGH, one MODERATE, denial of service in brace parsing). It reaches this repo only through minimatch under eslint and typescript-eslint, all dev dependencies (bun why brace-expansion). Both fixes already sat inside minimatch's declared ranges, so dependabot had nothing to propose and a plain install would never move the locked version; bun update brace-expansion relocks just those entries. Lockfile only, no manifest change.

Type of change

  • Bug fix (no breaking change)
  • New feature (no breaking change)
  • Breaking change (existing callers must update)
  • Docs, tests, or internal maintenance only

Public API

None. The lockfile is not published, so consumers are unaffected and no release is needed.

Test plan

bun install --frozen-lockfile, bun run lint, bun run typecheck and bun run test all exit 0 locally, and osv-scanner scan source -L bun.lock with the repo's config reports no issues.

Checklist

  • Tests cover the new behavior, and the suite passes locally: no new behavior; the existing suite passes
  • Lint, format, and type checks pass
  • Docs and README examples updated if the public surface changed: the public surface did not change
  • No secrets, credentials, or personal data in the diff or the tests

@vvillait88
vvillait88 merged commit 84cf431 into main Sep 30, 2026
6 checks passed
@vvillait88
vvillait88 deleted the chore/advisory-relock-2026-09-29 branch September 30, 2026 03:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant