Skip to content

fix(deps): bump brace-expansion to 5.0.7 for CVE-2026-13149#273

Merged
heznpc merged 1 commit into
mainfrom
fix/brace-expansion-dos
Jul 23, 2026
Merged

fix(deps): bump brace-expansion to 5.0.7 for CVE-2026-13149#273
heznpc merged 1 commit into
mainfrom
fix/brace-expansion-dos

Conversation

@heznpc

@heznpc heznpc commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Closes Dependabot alert #11 (high, dev scope): DoS via exponential-time expansion in brace-expansion >=3.0.0 <5.0.7 (CVE-2026-13149).

Two nested copies (eslint, @eslint/config-array) were at 5.0.6 → 5.0.7. Lockfile-only; npm audit now reports 0 vulnerabilities. Local verification: 617 jest tests + eslint green.

Dependabot alert #11 (high): DoS via exponential-time expansion of
consecutive non-expanding {} groups in brace-expansion >=3.0.0 <5.0.7.
Two nested copies (eslint, @eslint/config-array) were at 5.0.6.
Lockfile-only update; npm audit now reports 0 vulnerabilities.
Verified locally: 617 jest tests + eslint green.
@heznpc
heznpc merged commit 22143f9 into main Jul 23, 2026
8 checks passed
@heznpc
heznpc deleted the fix/brace-expansion-dos branch July 23, 2026 09:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant