Skip to content

fix: update brace-expansion to 5.0.6 (alert #31)#432

Closed
simon-lowes wants to merge 1 commit into
mainfrom
fix/security-brace-expansion-31
Closed

fix: update brace-expansion to 5.0.6 (alert #31)#432
simon-lowes wants to merge 1 commit into
mainfrom
fix/security-brace-expansion-31

Conversation

@simon-lowes

Copy link
Copy Markdown
Owner

Resolves Dependabot alert #31 (medium severity).

  • Package: brace-expansion
  • Vulnerable: >= 5.0.0, < 5.0.6
  • Patched: 5.0.6
  • Relationship: transitive (via @typescript-eslint/parser → typescript-estree → minimatch@10)

Only package-lock.json changed. Other minimatch chains in the tree use v1.x/v2.x which are not affected by the advisory.

🤖 Generated with Claude Code

Resolves Dependabot alert #31 (medium severity).
Transitive dep via @typescript-eslint/parser -> typescript-estree -> minimatch@10.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@simon-lowes

Copy link
Copy Markdown
Owner Author

Obsolete: duplicate of #430; main already has brace-expansion at patched versions (1.1.15 / 2.1.1 / 5.0.6). CVE already remediated.

@simon-lowes simon-lowes closed this Jun 9, 2026
@simon-lowes simon-lowes deleted the fix/security-brace-expansion-31 branch June 9, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant