Bump brace-expansion from 2.0.1 to 2.1.4 - #172
Conversation
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 2.0.1 to 2.1.4. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.1...v2.1.4) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 2.1.4 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
|
Caution Review the following alerts detected in dependencies. According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.
|
## Motivation Five open dependabot PRs, all lockfile-only transitive bumps, all currently red because they were branched before the Forge CI fix in #175. They also all edit the same two lockfiles, so merging them one at a time forces the rest to rebase and burns a CI run each time. Bundling them means one review and one CI run instead of five. Supersedes #168, #169, #170, #171 and #172. Dependabot's commits are cherry-picked unchanged, so authorship and the advisory trail are preserved. | PR | Bump | Advisory | | --- | --- | --- | | #172 | brace-expansion 2.0.1 to 2.1.4 | GHSA-mh99-v99m-4gvg, CVE-2026-13149 (ReDoS) | | #170 | pbkdf2 3.1.2 to 3.1.6 | CVE-2025-6545, CVE-2025-6547 (predictable key material) | | #168 | immutable 4.1.0 to 4.3.9 | GHSA-v56q-mh7h-f735, GHSA-xvcm-6775-5m9r, CVE-2026-29063 | | #169 | immutable 4.1.0 to 4.3.9, vendored OZ copy | as above | | #171 | min-document 2.19.0 to 2.19.2, vendored OZ copy | transitive | ## Solution Two files change and both are lockfiles. No `package.json`, no contract source, no submodule. None of these five packages appears in this repo's `dependencies` or `devDependencies`, so every one is transitive. `yarn.lock` is not published to npm, so no consumer of the package is affected. The Solidity dependencies come from the git submodules in `.gitmodules` rather than npm, so the contracts are untouched. `src-upgradeable/lib-upgradeable/utility-contracts/lib/openzeppelin-contracts/package-lock.json` is a vendored copy of OpenZeppelin, not a submodule, and nothing in the build reads that lockfile. Those two entries (#169 and #171) are inert, and are included here to close out the queue rather than because they change behavior. ## Verification Resolved versions after bundling: ``` yarn.lock brace-expansion 2.1.4 pbkdf2 3.1.6 immutable 4.3.9 vendored OZ lock immutable 4.3.9 min-document 2.19.2 ``` All five cherry-picks applied without conflict, and the diff against `main` touches nothing but the two lockfiles. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
Looks like brace-expansion is up-to-date now, so this is no longer needed. |
Bumps brace-expansion from 2.0.1 to 2.1.4.
Release notes
Sourced from brace-expansion's releases.
Commits
b25213d2.1.41e30c93Merge commit from fork878df392.1.3c8bd93cnpm ignore .clauded13ff45fix: backport GHSA-mh99-v99m-4gvg (#130)9e67a3b2.1.2835d6befix: v2 backport for CVE-2026-13149 (#123)64b71d32.1.1c3a817cBackport v5.0.6 change to v2 (#109)1ee4a902.1.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.