chore(deps): bump brace-expansion from 5.0.7 to 5.0.9 - #571
chore(deps): bump brace-expansion from 5.0.7 to 5.0.9#571dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.7 to 5.0.9. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.7...v5.0.9) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.9 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
imMamdouhaboammar
left a comment
There was a problem hiding this comment.
Reviewed the lockfile-only change. The diff is limited to brace-expansion 5.0.7 -> 5.0.9 plus its integrity and Node engine metadata, the target's Node range remains compatible with this repository, the PR is currently mergeable, and its workflow run is green. No blocking issues found.
…ity-patch fix(ai): align antigravity request payload
…er in interactive mode
Adds the reviewed bumps from #571, #599, #713, and #714 to the consolidated update: - brace-expansion 5.0.7 -> 5.0.9 (transitive, lockfile only) - ip-address 10.2.0 -> 10.4.0 (transitive, lockfile only) - typebox ^1.1.24 -> ^1.3.9 in packages/agent, packages/ai, and packages/coding-agent (lockfile resolves 1.3.10, released 2026-08-02, past the seven-day minimum release age) - typescript ^5.9.2/^5.7.3 -> ^7.0.2 (dev-only; every build and check in this repo runs through tsgo, nothing invokes tsc) undici 8.9.0 from #712 is intentionally NOT included: undici 8 requires Node >= 22.19.0 while this package supports >= 22.8.0, so the major bump would silently drop supported Node versions. It stays on 7.29.0.
|
Folded into the consolidated dependency update #632 (brace-expansion 5.0.9); see that PR for validation. Closing in its favor. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
* chore(deps): consolidate dependency updates * chore(deps): fold in remaining eligible Dependabot updates Adds the reviewed bumps from #571, #599, #713, and #714 to the consolidated update: - brace-expansion 5.0.7 -> 5.0.9 (transitive, lockfile only) - ip-address 10.2.0 -> 10.4.0 (transitive, lockfile only) - typebox ^1.1.24 -> ^1.3.9 in packages/agent, packages/ai, and packages/coding-agent (lockfile resolves 1.3.10, released 2026-08-02, past the seven-day minimum release age) - typescript ^5.9.2/^5.7.3 -> ^7.0.2 (dev-only; every build and check in this repo runs through tsgo, nothing invokes tsc) undici 8.9.0 from #712 is intentionally NOT included: undici 8 requires Node >= 22.19.0 while this package supports >= 22.8.0, so the major bump would silently drop supported Node versions. It stays on 7.29.0.
* chore(deps): consolidate dependency updates * chore(deps): fold in remaining eligible Dependabot updates Adds the reviewed bumps from PrimeIntellect-ai#571, PrimeIntellect-ai#599, PrimeIntellect-ai#713, and PrimeIntellect-ai#714 to the consolidated update: - brace-expansion 5.0.7 -> 5.0.9 (transitive, lockfile only) - ip-address 10.2.0 -> 10.4.0 (transitive, lockfile only) - typebox ^1.1.24 -> ^1.3.9 in packages/agent, packages/ai, and packages/coding-agent (lockfile resolves 1.3.10, released 2026-08-02, past the seven-day minimum release age) - typescript ^5.9.2/^5.7.3 -> ^7.0.2 (dev-only; every build and check in this repo runs through tsgo, nothing invokes tsc) undici 8.9.0 from PrimeIntellect-ai#712 is intentionally NOT included: undici 8 requires Node >= 22.19.0 while this package supports >= 22.8.0, so the major bump would silently drop supported Node versions. It stays on 7.29.0.
Bumps brace-expansion from 5.0.7 to 5.0.9.
Commits
fbcf8ec5.0.9f6f3939test: cover dropping empties when only some prefixes are empty688a99eMerge commit from forkc66e5f9docs: make the maxLength example produce a non-empty result (#137)473d3e9Bump linkify-it from 5.0.1 to 5.0.2 (#128)96a63c05.0.8a1bd339Merge commit from fork592a36fBump tar from 7.5.16 to 7.5.20 (#127)bd14690Bump brace-expansion from 2.0.2 to 2.1.2 (#126)e729ba6Bump ws from 8.19.0 to 8.21.1 (#124)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Note
Low Risk
Indirect dependency patch in the lockfile only; no application code changes, and the repo already targets Node 22+.
Overview
Updates the lockfile so transitive
brace-expansion(viaminimatch) moves from 5.0.7 to 5.0.9. No directpackage.jsondependency changes.Upstream 5.0.8–5.0.9 includes security-related merges, extra tests, and doc fixes; the resolved package’s Node engine range is now
20 || >=22(dropping 18), which aligns with this repo’s>=22.8.0engine requirement.Reviewed by Cursor Bugbot for commit 8f2d8d7. Bugbot is set up for automated code reviews on this repo. Configure here.
Note
Bump
brace-expansiondependency from 5.0.7 to 5.0.9Updates
brace-expansionin package-lock.json to version 5.0.9.Macroscope summarized 8f2d8d7.