Skip to content

chore(deps): upgrade brace-expansion to 5.0.5 to address CVE-2026-33750#24

Merged
fern-support merged 1 commit intomainfrom
devin/1774880847-fix-brace-expansion-cve
Mar 30, 2026
Merged

chore(deps): upgrade brace-expansion to 5.0.5 to address CVE-2026-33750#24
fern-support merged 1 commit intomainfrom
devin/1774880847-fix-brace-expansion-cve

Conversation

@davidkonigsberg
Copy link
Copy Markdown
Contributor

@davidkonigsberg davidkonigsberg commented Mar 30, 2026

Summary

Regenerate package-lock.json to resolve brace-expansion from 5.0.3 → 5.0.5, fixing Dependabot alert #20 (GHSA-f886-m6hf-6m8v / CVE-2026-33750). Rebuild dist/ to include the patched dependency.

No override or package.json change was needed — the existing ^5.0.2 range from minimatch/glob already allows 5.0.5; the lockfile was simply pinned to the older 5.0.3.

The dist/index.js diff reflects the upstream fix: zero-step increments are now sanitized to Math.max(..., 1) to prevent infinite loops and memory exhaustion.

Review & Testing Checklist for Human

Notes

  • No source code or package.json changes — only package-lock.json and the rebuilt dist/index.js bundle.

Link to Devin session: https://app.devin.ai/sessions/15636fcafbed48cea2c2447ead2650ef
Requested by: @davidkonigsberg

Regenerate package-lock.json to resolve brace-expansion from 5.0.3 to
5.0.5, fixing Dependabot alert #20 (GHSA-f886-m6hf-6m8v).
Rebuild dist to include the patched dependency.

Co-Authored-By: David Konigsberg <davidakonigsberg@gmail.com>
@devin-ai-integration devin-ai-integration bot force-pushed the devin/1774880847-fix-brace-expansion-cve branch from dc0b779 to c71a606 Compare March 30, 2026 14:45
@fern-support fern-support merged commit f0a1908 into main Mar 30, 2026
1 check passed
@fern-support fern-support deleted the devin/1774880847-fix-brace-expansion-cve branch March 30, 2026 14:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants