Skip to content

fix: update vulnerable brace-expansion dev dependency - #247

Merged
bifrost0x merged 1 commit into
mainfrom
dev/fix-brace-expansion-5-0-12
Oct 2, 2026
Merged

bifrost0x merged 1 commit into
mainfrom
dev/fix-brace-expansion-5-0-12

Conversation

@bifrost0x

Copy link
Copy Markdown
Owner

Updates the transitive ESLint development dependency brace-expansion from 5.0.9 to 5.0.12 in package-lock.json. The patched version resolves GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, and GHSA-6j4f-fj2g-mc7p.

The production dependency set and vendored browser assets are unchanged.

Local checks: npm ci --ignore-scripts, npm audit --package-lock-only (0 findings), npm audit --omit=dev (0 findings), npm run vendor:check, npm run lint:js, and 671 JavaScript unit tests. The full workflow will verify the Linux CI gates.

@bifrost0x
bifrost0x marked this pull request as ready for review October 2, 2026 20:59
@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T21:00:37.621003Z 350e419 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@bifrost0x
bifrost0x merged commit dc3d9bf into main Oct 2, 2026
26 checks passed
@bifrost0x
bifrost0x deleted the dev/fix-brace-expansion-5-0-12 branch October 2, 2026 21:01
@bifrost0x bifrost0x mentioned this pull request Oct 3, 2026
7 tasks done
@bifrost0x bifrost0x added this to the v2.5.0 milestone Oct 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant