chore(deps): bump brace-expansion to clear three npm advisories - #2884
Merged
Merged
Conversation
npm audit in the build image flagged brace-expansion <=1.1.20 and 4.0.0 to 5.0.11 (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p), which turned SAST Frontend red on every PR. The lockfile was regenerated with `npm audit fix --package-lock-only` in the Dockerfile's node:26-alpine image (npm 11.19.1): 1.1.18 to 1.1.21 and 5.0.9 to 5.0.12, all dev tooling (eslint, glob), MIT. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016fJcCVbNnKsmj2MAAMwWj9 Signed-off-by: vavallee <vavallee@protonmail.com>
Contributor
There was a problem hiding this comment.
Lockfile-only bump, all five updated entries carry "dev": true — nothing ships in the app bundle.
brace-expansion1.1.18 → 1.1.21 (four transitive copies:@eslint/eslintrc,@humanwhocodes/config-array,@microsoft/eslint-formatter-sarif,glob)brace-expansion5.0.9 → 5.0.12 (top-level dev dep)
All three GHSAs (DoS / CPU+stack exhaustion) are addressed. package.json is unchanged, which is correct for a transitive-only fix via --package-lock-only. Changelog fragment present. No concerns.
— 🤖 Bindery triage bot (automated). Reply to correct me; a human will see it.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
npm auditflagsbrace-expansion<=1.1.20 and 4.0.0 to 5.0.11 (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p, high, CPU and stack exhaustion denial of service), which has turned SAST Frontend red on every new PR since the advisories landed.Only
web/package-lock.jsonchanges: 1.1.18 to 1.1.21 (four nested copies under eslint,@microsoft/eslint-formatter-sarif,@humanwhocodes/config-array, glob) and 5.0.9 to 5.0.12. All are dev tooling; nothing ships in the app bundle.How it was verified
node:26-alpineimage (npm 11.19.1) withnpm audit fix --package-lock-only, sonpm ciin the image build agrees with it;npm auditthen reports 0 vulnerabilities.npm ciandnpm run buildsucceed.npm ci, eslint clean, vitest 1173 passed,make licenses-checkreports THIRD_PARTY_LICENSES.md up to date.🤖 Generated with Claude Code
https://claude.ai/code/session_016fJcCVbNnKsmj2MAAMwWj9