Skip to content

fix(deps): bump brace-expansion to 5.0.12 - #87

Merged
florianmousseau merged 1 commit into
mainfrom
fix/brace-expansion-5.0.12
Sep 30, 2026
Merged

florianmousseau merged 1 commit into
mainfrom
fix/brace-expansion-5.0.12

Conversation

@florianmousseau

Copy link
Copy Markdown
Contributor

Three brace-expansion DoS advisories (high) were published and no Dependabot PR covers them yet.

Lockfile, package by package: brace-expansion 5.0.9 -> 5.0.12 (dev, via minimatch). Nothing added, nothing else changed; nothing ships in the package.

npm audit --audit-level=high --package-lock-only: exit 1 before, exit 0 after.

@claude

claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @florianmousseau's task in 16s —— View job


Review checklist

  • Gather context (diff, package.json, commit log)
  • Review change against quality-gate criteria

Findings

Clean. This is a lockfile-only dependency bump (brace-expansion 5.0.9 → 5.0.12, transitive dev dependency via minimatch), 3 insertions / 3 deletions, no source files touched. Nothing to flag against the review criteria (no dead code, no duplication, no speculative abstraction, no architectural drift, no tests, no swallowed errors, no new dependency introduced — just a patched version of an existing transitive dep).

@florianmousseau
florianmousseau merged commit 58e4aad into main Sep 30, 2026
7 checks passed
@florianmousseau
florianmousseau deleted the fix/brace-expansion-5.0.12 branch September 30, 2026 21:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant