Skip to content

chore: Bump brace-expansion from 5.0.6 to 5.0.8 - #158

Merged
pan-kot merged 1 commit into
mainfrom
dependabot/npm_and_yarn/brace-expansion-5.0.8
Jul 24, 2026
Merged

chore: Bump brace-expansion from 5.0.6 to 5.0.8#158
pan-kot merged 1 commit into
mainfrom
dependabot/npm_and_yarn/brace-expansion-5.0.8

Conversation

@ernst-dev

Copy link
Copy Markdown
Member

Bumps brace-expansion from 5.0.6 to 5.0.8 to address a Regular Expression Denial of Service (ReDoS) vulnerability.

Lockfile-only change (transitive dependency; package-lock.json only). Only the node_modules/minimatch/node_modules/brace-expansion entry changes (dependency set unchanged: balanced-match ^4.0.2).

  • Advisory: GHSA-3jxr-9vmj-r5cp (High)
  • Vulnerable versions: >= 3.0.0, < 5.0.7Patched version: 5.0.7 (bumped to latest 5.0.8)

Opened by roko-dependabot-handler on behalf of @ernst-dev to remediate a Dependabot alert that had no auto-generated fix.

@ernst-dev ernst-dev added the dependencies Pull requests that update a dependency file label Jul 23, 2026
@ernst-dev
ernst-dev requested a review from a team as a code owner July 23, 2026 11:54
@ernst-dev
ernst-dev requested review from pan-kot and removed request for a team July 23, 2026 11:54
@codecov

codecov Bot commented Jul 23, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (7300655) to head (7161067).

Additional details and impacted files
@@            Coverage Diff            @@
##              main      #158   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            9         9           
  Lines           78        78           
  Branches        21        21           
=========================================
  Hits            78        78           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@pan-kot
pan-kot added this pull request to the merge queue Jul 24, 2026
Merged via the queue into main with commit 89493fa Jul 24, 2026
47 checks passed
@pan-kot
pan-kot deleted the dependabot/npm_and_yarn/brace-expansion-5.0.8 branch July 24, 2026 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants