Skip to content

chore(deps): bump brace-expansion to clear three npm advisories - #2884

Merged
vavallee merged 1 commit into
mainfrom
fix/npm-brace-expansion-advisory
Oct 1, 2026
Merged

vavallee merged 1 commit into
mainfrom
fix/npm-brace-expansion-advisory

Conversation

@vavallee

@vavallee vavallee commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

npm audit flags brace-expansion <=1.1.20 and 4.0.0 to 5.0.11 (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, high, CPU and stack exhaustion denial of service), which has turned SAST Frontend red on every new PR since the advisories landed.

Only web/package-lock.json changes: 1.1.18 to 1.1.21 (four nested copies under eslint, @microsoft/eslint-formatter-sarif, @humanwhocodes/config-array, glob) and 5.0.9 to 5.0.12. All are dev tooling; nothing ships in the app bundle.

How it was verified

  • Lockfile regenerated inside the Dockerfile's pinned node:26-alpine image (npm 11.19.1) with npm audit fix --package-lock-only, so npm ci in the image build agrees with it; npm audit then reports 0 vulnerabilities.
  • In that image: npm ci and npm run build succeed.
  • Locally: npm ci, eslint clean, vitest 1173 passed, make licenses-check reports THIRD_PARTY_LICENSES.md up to date.
  • Licence read from each installed copy's LICENSE file: MIT.

🤖 Generated with Claude Code

https://claude.ai/code/session_016fJcCVbNnKsmj2MAAMwWj9

npm audit in the build image flagged brace-expansion <=1.1.20 and
4.0.0 to 5.0.11 (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7,
GHSA-6j4f-fj2g-mc7p), which turned SAST Frontend red on every PR. The
lockfile was regenerated with `npm audit fix --package-lock-only` in the
Dockerfile's node:26-alpine image (npm 11.19.1): 1.1.18 to 1.1.21 and
5.0.9 to 5.0.12, all dev tooling (eslint, glob), MIT.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016fJcCVbNnKsmj2MAAMwWj9
Signed-off-by: vavallee <vavallee@protonmail.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lockfile-only bump, all five updated entries carry "dev": true — nothing ships in the app bundle.

  • brace-expansion 1.1.18 → 1.1.21 (four transitive copies: @eslint/eslintrc, @humanwhocodes/config-array, @microsoft/eslint-formatter-sarif, glob)
  • brace-expansion 5.0.9 → 5.0.12 (top-level dev dep)

All three GHSAs (DoS / CPU+stack exhaustion) are addressed. package.json is unchanged, which is correct for a transitive-only fix via --package-lock-only. Changelog fragment present. No concerns.

— 🤖 Bindery triage bot (automated). Reply to correct me; a human will see it.

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@vavallee
vavallee merged commit bf82d83 into main Oct 1, 2026
42 of 43 checks passed
@vavallee
vavallee deleted the fix/npm-brace-expansion-advisory branch October 1, 2026 03:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant