Skip to content

fix(deps): bump brace-expansion 5.0.6 -> 5.0.7 - #238

Merged
stevenfackley merged 2 commits into
mainfrom
fix/deps-brace-expansion
Jul 23, 2026
Merged

fix(deps): bump brace-expansion 5.0.6 -> 5.0.7#238
stevenfackley merged 2 commits into
mainfrom
fix/deps-brace-expansion

Conversation

@stevenfackley

Copy link
Copy Markdown
Owner

Summary

npm update brace-expansion in src/StackAlchemist.Web — lockfile-only change. Clears Dependabot alert #48 (high, >= 3.0.0, < 5.0.7). Root instance now 5.0.7 (satisfies minimatch ^5.0.5); nested 1.1.x eslint-chain copies are outside the vulnerable range.

Clears Dependabot alert #48 (high, vulnerable range >=3.0.0 <5.0.7).
Root instance satisfies minimatch ^5.0.5; nested 1.1.x eslint-chain
copies are outside the vulnerable range (refreshed to 1.1.16 by the
same npm update).
The CI Audit Dependencies step failed on sharp <0.35.0 (libvips CVEs,
GHSA-f88m-g3jw-g9cj). npm audit displayed this as a wall of next
advisories, but that was the metavulnerability rollup: next was flagged
only for depending on vulnerable sharp. Flooring sharp (0.34.5 ->
0.35.3) takes npm audit to 0 vulnerabilities; no gate change needed.

Same sharp@0 override pattern as haulcall and trailtold.
@stevenfackley
stevenfackley merged commit 1128c3a into main Jul 23, 2026
16 checks passed
@stevenfackley
stevenfackley deleted the fix/deps-brace-expansion branch July 23, 2026 06:50
stevenfackley added a commit that referenced this pull request Jul 23, 2026
* fix(deps): resolve known security vulnerabilities

Bump vulnerable dependencies flagged by the GitHub/OSV advisory database:
npm audit fixes, upward-only direct bumps, and scoped overrides for
transitive packages (brace-expansion, shell-quote, postcss, esbuild, ws,
undici, minimatch, glob, cookie); pnpm overrides; lockfile re-resolution.
No dependency was downgraded (verified against HEAD).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1

* fix(deps): repair lockfile consistency and override resolution

- Regenerate complete lockfiles with full npm install (npm ci was failing
  on missing entries from --package-lock-only updates)
- Constrain brace-expansion overrides per-major (1.1.16 / 2.1.2 / 5.0.7);
  the audit-fix '>=1.1.16' override was jumping minimatch's dependency
  across majors and breaking ESLint at runtime
- Cap vitest override at ~3.2.6 where vite 5 is in use (vitest 4 needs vite 6)
- ai-fit: add required TextArea props surfaced by react-native type bump

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1

* fix(deps): bump brace-expansion 5.0.6 -> 5.0.7 (#238)

* fix(deps): bump brace-expansion 5.0.6 -> 5.0.7

Clears Dependabot alert #48 (high, vulnerable range >=3.0.0 <5.0.7).
Root instance satisfies minimatch ^5.0.5; nested 1.1.x eslint-chain
copies are outside the vulnerable range (refreshed to 1.1.16 by the
same npm update).

* fix(deps): floor sharp at 0.35.0+ via override — clears npm audit gate

The CI Audit Dependencies step failed on sharp <0.35.0 (libvips CVEs,
GHSA-f88m-g3jw-g9cj). npm audit displayed this as a wall of next
advisories, but that was the metavulnerability rollup: next was flagged
only for depending on vulnerable sharp. Flooring sharp (0.34.5 ->
0.35.3) takes npm audit to 0 vulnerabilities; no gate change needed.

Same sharp@0 override pattern as haulcall and trailtold.

* fix(deps): resolve current security advisories (refreshed against latest main)

Rebuilt from today's main and today's advisory set: npm audit fixes,
upward-only direct bumps, per-major overrides for transitive packages,
pnpm override sanitation, uv.lock/cargo/requirements updates.
Verified: no dependency downgraded; lockfiles npm-ci-consistent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_011ZwgeVpoxnDRL78Dw1bSu1

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant