Skip to content

Bump brace-expansion - #164

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-05c505ab13
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/multi-05c505ab13

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps and brace-expansion. These dependencies needed to be updated together.
Updates brace-expansion from 5.0.5 to 5.0.12

Commits

Updates brace-expansion from 1.1.11 to 1.1.21

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 5.0.5 to 5.0.12
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.5...v5.0.12)

Updates `brace-expansion` from 1.1.11 to 1.1.21
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v5.0.5...v5.0.12)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 5.0.12
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 2, 2026
@dependabot dependabot Bot mentioned this pull request Oct 2, 2026
@fossabot

fossabot Bot commented Oct 2, 2026

Copy link
Copy Markdown

⏳ Analysis Queued

Your fossabot analysis was queued at 2026-10-02 16:25:17 UTC. We'll start as soon as a worker picks it up.


fossabot will update this comment as the analysis progresses.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: c3b94157-e413-498d-9f41-171a2d7bced8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@fossabot

fossabot Bot commented Oct 2, 2026

Copy link
Copy Markdown

fossabot Analysis Paused

App impact analysis skipped — out of credits

Breaking change detection completed but more credits are needed to enable usage detection, impact analysis, fix suggestions, and get your final upgrade determination.

brace-expansion 5.0.5 → 5.0.12

We found 1 breaking change and 3 security fixes.

  • Dropped support for Node.js 18. Engine requirement changed from 'node: 18 || 20 || >=22' to 'node: 20 || >=22'. Users on Node.js 18 must upgrade to Node.js 20+ to use this version. (v5.0.8, package source)
  • Added maxLength option to prevent memory exhaustion attacks (CVE-2026-14257). New EXPANSION_MAX_LENGTH constant (4_000_000) bounds total character count across all expansions to prevent DoS through long individual results. (v5.0.8, package source)
  • Refactored parseCommaParts function from recursive to iterative implementation to prevent stack overflow on deeply nested brace expansions (CVE-2026-14257) (v5.0.10, package source)
View more changes for brace-expansion
  • Fix package.json to use git+https instead of git+ssh for repository URL (v5.0.6-5.0.7, commit)
  • Update and correct CI/test workflow (ci.yml) (v5.0.6-5.0.7, commit)
  • Add test coverage for dropping empties when only some prefixes are empty (v5.0.8-5.0.9, commit)
  • Fix maxLength example to produce a non-empty result (v5.0.8-5.0.9, commit)
  • Bump ip-address from 10.1.0 to 10.2.0 (v5.0.6-5.0.7, commit)
  • Bump ip-address from 10.2.0 to 10.4.0 (v5.0.9-5.0.10, commit)
  • Bump picomatch from 4.0.3 to 4.0.4 (v5.0.5-5.0.6, commit)
  • Bump tar from 7.5.11 to 7.5.16 (v5.0.6-5.0.7, commit)
  • Bump minimatch (v5.0.6-5.0.7, commit)
  • Merge commit from fork (v5.0.6-5.0.7, commit)

...and 25 more in the full analysis


You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

Mute out-of-credit notifications until next month (expires 2026-11-01T00:00:00.000Z)

1 similar comment
@fossabot

fossabot Bot commented Oct 2, 2026

Copy link
Copy Markdown

fossabot Analysis Paused

App impact analysis skipped — out of credits

Breaking change detection completed but more credits are needed to enable usage detection, impact analysis, fix suggestions, and get your final upgrade determination.

brace-expansion 5.0.5 → 5.0.12

We found 1 breaking change and 3 security fixes.

  • Dropped support for Node.js 18. Engine requirement changed from 'node: 18 || 20 || >=22' to 'node: 20 || >=22'. Users on Node.js 18 must upgrade to Node.js 20+ to use this version. (v5.0.8, package source)
  • Added maxLength option to prevent memory exhaustion attacks (CVE-2026-14257). New EXPANSION_MAX_LENGTH constant (4_000_000) bounds total character count across all expansions to prevent DoS through long individual results. (v5.0.8, package source)
  • Refactored parseCommaParts function from recursive to iterative implementation to prevent stack overflow on deeply nested brace expansions (CVE-2026-14257) (v5.0.10, package source)
View more changes for brace-expansion
  • Fix package.json to use git+https instead of git+ssh for repository URL (v5.0.6-5.0.7, commit)
  • Update and correct CI/test workflow (ci.yml) (v5.0.6-5.0.7, commit)
  • Add test coverage for dropping empties when only some prefixes are empty (v5.0.8-5.0.9, commit)
  • Fix maxLength example to produce a non-empty result (v5.0.8-5.0.9, commit)
  • Bump ip-address from 10.1.0 to 10.2.0 (v5.0.6-5.0.7, commit)
  • Bump ip-address from 10.2.0 to 10.4.0 (v5.0.9-5.0.10, commit)
  • Bump picomatch from 4.0.3 to 4.0.4 (v5.0.5-5.0.6, commit)
  • Bump tar from 7.5.11 to 7.5.16 (v5.0.6-5.0.7, commit)
  • Bump minimatch (v5.0.6-5.0.7, commit)
  • Merge commit from fork (v5.0.6-5.0.7, commit)

...and 25 more in the full analysis


You have no credits left. Reach out to autoupdates@fossa.com and we'll top you up.

Credits are consumed when dependency updates are reviewed or proposed.

Re-run with @fossabot analyze.

Mute out-of-credit notifications until next month (expires 2026-11-01T00:00:00.000Z)

@depintel-bot

depintel-bot Bot commented Oct 2, 2026

Copy link
Copy Markdown

🟢 Ready to merge

🟢 Ready to merge

Lapisa checked (lockfile) - → - against the interfaces this repository uses; no affected usage was found.

View evidence and analysis receipt

depintel verdict: safe

Package: (lockfile) - -> -

review lockface-a06a1c96-clean · engine 0d8289a4

Impact: NONE found — OK to merge on this evidence.

lock-only refresh: no phantom-direct hits — indirect resolution moves are the declared deps' maintainers' responsibility face (reviewed law); lock locations added 0 / removed 0 / modified 6

additional: lock location inventory
  • modified: node_modules/@eslint/config-array/node_modules/brace-expansion
  • modified: node_modules/brace-expansion
  • modified: node_modules/eslint/node_modules/brace-expansion
  • modified: node_modules/nyc/node_modules/brace-expansion
  • modified: node_modules/rimraf/node_modules/brace-expansion
  • modified: node_modules/test-exclude/node_modules/brace-expansion

Basis: lock-only refresh: no phantom-direct hits — indirect resolution moves are the declared deps' maintainers' responsibility face (reviewed law); lock locations added 0 / removed 0 / modified 6

additional: lock location inventory
  • modified: node_modules/@eslint/config-array/node_modules/brace-expansion
  • modified: node_modules/brace-expansion
  • modified: node_modules/eslint/node_modules/brace-expansion
  • modified: node_modules/nyc/node_modules/brace-expansion
  • modified: node_modules/rimraf/node_modules/brace-expansion
  • modified: node_modules/test-exclude/node_modules/brace-expansion

Run: 20261002T162902Z-146967074dd2


Evidence is static analysis plus release evidence available to depintel at run time. This advisory verdict is not a substitute for maintainer review.

@depintel-bot depintel-bot Bot added the lapisa:safe Ready to merge - no affected usage label Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code lapisa:safe Ready to merge - no affected usage

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants