Skip to content

chore(deps): bump brace-expansion from 1.1.14 to 1.1.18 in /test-projects/expo-purchasely-test - #271

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/brace-expansion-1.1.18
Open

chore(deps): bump brace-expansion from 1.1.14 to 1.1.18 in /test-projects/expo-purchasely-test#271
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/brace-expansion-1.1.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.14 to 1.1.18.

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.14 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/commits)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 3, 2026
@greptile-apps

greptile-apps Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

Copy link
Copy Markdown

Dependabot review — 2026-08-04 (research only, no merge/approve action taken)

Tracking summary for all 4 currently open Dependabot PRs posted on #269: #269 (comment) (Issues are disabled on this repo, so a PR comment hosts the summary instead of a GitHub issue).

This PR: brace-expansion 1.1.14 → 1.1.18 (patch). CI: build-ios failing while the other 6 checks (including the parallel build-rn-0-86-ios) are green. No merge conflicts, no hold label. Not auto-merging pending confirmation the build-ios failure is unrelated/flaky. Nothing merges until a human approves on the #269 tracking comment.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-08-08) is posted on #269 (GitHub Issues are disabled on this repo) — covers this PR plus #272, #273, #274, #269. This PR: brace-expansion 1.1.14 → 1.1.18 (patch, likely the GHSA-mh99-v99m-4gvg ReDoS backport), CI red on build-ios only (6/7 pass). See #269 for the full table and next steps — nothing merges without a human go-ahead there.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-08-09) is posted on #269 (GitHub Issues are still disabled on this repo) — covers this PR plus #272, #273, #274, #269. This PR: brace-expansion 1.1.14 → 1.1.18 (patch, likely the GHSA-mh99-v99m-4gvg ReDoS backport), CI red on build-ios only (6/7 pass). See #269 for the full table and next steps — nothing merges without a human go-ahead there.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-08-12 (research only, no merge/approve/rebase action taken)

Old tracking host #269 was closed (superseded by Dependabot itself when it opened #276) on 2026-08-11, so this comment on #271 — the oldest still-open PR in the batch — is now the tracking host. GitHub Issues are disabled on this repo, so a PR comment hosts the summary instead of a GitHub issue (same workaround used since 2026-08-04).

Current batch (7 open Dependabot PRs)

# Package Version Change Bump CI Action
#277 nanoid 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked (see root cause below)
#276 postcss (test-projects) 8.5.12→8.5.26 minor 🔴 build-ios only (6/7 pass) Supersedes closed #269. Auto-merge candidate once unblocked
#275 nanoid (test-projects) 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#274 undici (root) 7.28.0→7.29.0 minor — 5 CVE fixes (cache poisoning, header CRLF injection, content-length desync, cookie injection) 🔴 all 7 checks failing — the outlier, unchanged since its 2026-08-04 run Needs a fresh CI run (rebase) to see if it's just the same build-ios issue as the others or a real regression. Prioritize once green — genuine security content
#273 undici (test-projects) 8.5.0→8.10.0 minor 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#272 fast-uri (test-projects) 4.1.1→4.1.2 patch — security advisory GHSA-7p8r-x3mc-p8w7 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#271 (this PR) brace-expansion (test-projects) 1.1.14→1.1.18 patch — likely GHSA-mh99-v99m-4gvg ReDoS backport 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked

No merge conflicts on any of the 7 (mergeable_state: blocked throughout, never dirty). No hold labels. All 7 bumps are minor/patch — no majors in this batch.

Root cause of the shared build-ios failure — and the fix is already open

Every PR above fails build-ios for the identical reason: Xcode 26's "Explicitly Built Modules" build setting can't resolve the plain #import "react_native_purchasely-Swift.h" in PurchaselyRN.m as a dependency edge on the pod's own module, so the Swift compile isn't guaranteed to run first — 'react_native_purchasely-Swift.h' file not found.

PR #278 (open, unmerged, from @AurelienV-42) fixes exactly this by switching to a module-qualified #import <react_native_purchasely/react_native_purchasely-Swift.h> guarded by __has_include. Verified against a real Xcode 26 build per the PR description.

Recommendation: merge #278 first, then ·@·d·ependabot r·ebase (or let the next auto-rebase cycle handle it) on the 7 PRs above. Expect all of them except possibly #274 to go fully green and become clean auto-merge candidates — several carry real security fixes (undici, fast-uri, brace-expansion).

Nothing merged, approved, rebased, or closed this cycle — waiting on an explicit human go-ahead on this comment before any action. cc @kherembourg @romainsalles


Generated by Claude Code

Copy link
Copy Markdown

Dependabot review — 2026-08-13: 7 open PRs, action plan

Automated Dependabot review (scheduled). This repo has GitHub Issues disabled, so I'm using this PR thread (the oldest in the batch) as the confirmation gate instead of a tracking issue. No PRs have been merged, approved, or commented on otherwise — nothing happens until someone confirms here. cc @kherembourg (most recently active non-bot contributor on this repo) — could you take a look?

Summary

# Package Scope Version change Bump CI Action
#277 nanoid root 3.3.11 → 3.3.18 patch 🔴 red (build-ios only, 6/7 green) CI failing
#276 postcss test-projects/expo-purchasely-test 8.5.12 → 8.5.26 patch 🔴 red (build-ios only, 6/7 green) CI failing
#275 nanoid test-projects/expo-purchasely-test 3.3.11 → 3.3.18 patch 🔴 red (build-ios only, 6/7 green) CI failing
#274 undici root 7.28.0 → 7.29.0 minor (security) 🔴 red (all 7 checks) CI failing
#273 undici test-projects/expo-purchasely-test 8.5.0 → 8.10.0 minor (security) 🔴 red (build-ios only, 6/7 green) CI failing
#272 fast-uri test-projects/expo-purchasely-test 4.1.1 → 4.1.2 patch (security) 🔴 red (build-ios only, 6/7 green) CI failing
#271 (this PR) brace-expansion test-projects/expo-purchasely-test 1.1.14 → 1.1.18 patch 🔴 red (build-ios only, 6/7 green) CI failing

No major bumps in this batch. All 7 report mergeable_state: blocked (not GitHub's dirty/conflict state) and none carry a hold/wip label — CI is the only thing blocking every one of these.

Notable pattern: shared build-ios failure

6 of 7 PRs fail only on build-ios, with every other check (build-android, build-rn-0-86-ios, build-rn-0-86-android, test, lint, iOS unit tests) green. This strongly suggests a single pre-existing iOS build issue unrelated to any of these dependency bumps, rather than each bump independently breaking iOS. #274 (undici root) is the outlier — all 7 checks fail there, which may be a separate, real issue with that bump specifically (or simply a stale run — it was queued 2026-08-04 while the PR shows "updated" 2026-08-12, likely just Dependabot's rebase-check comment rather than a fresh CI run).

Priority once CI is unblocked

Proposed plan (pending confirmation)

  1. Investigate the shared build-ios failure — fixing the root cause would very likely unblock 6 of these 7 PRs at once.
  2. Separately check chore(deps): bump undici from 7.28.0 to 7.29.0 #274's full-red run — confirm whether it's a stale run needing a rebase/re-trigger, or a real break from the undici 7.29.0 bump.
  3. Once CI is green, merge in priority order: chore(deps): bump undici from 7.28.0 to 7.29.0 #274, chore(deps): bump undici from 8.5.0 to 8.10.0 in /test-projects/expo-purchasely-test #273, chore(deps): bump fast-uri from 4.1.1 to 4.1.2 in /test-projects/expo-purchasely-test #272 (security-relevant) first, then the remaining patch bumps.

Reply here to confirm this plan, or let me know if you'd rather I just trigger reruns/rebases first and reassess.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant