Skip to content

fix: resolve CVE-2026-45149 brace-expansion DoS vulnerability#218

Merged
lamnhoan merged 1 commit into
mainfrom
fix/dependabot-brace-expansion
May 20, 2026
Merged

fix: resolve CVE-2026-45149 brace-expansion DoS vulnerability#218
lamnhoan merged 1 commit into
mainfrom
fix/dependabot-brace-expansion

Conversation

@lamnhoan

Copy link
Copy Markdown
Contributor

Resolves Dependabot alert #87 (CVE-2026-45149): brace-expansion large numeric range defeats documented max DoS protection.

Applied npm audit fix — only package-lock.json changed.

@lamnhoan lamnhoan requested a review from a team as a code owner May 18, 2026 21:13
@lamnhoan lamnhoan merged commit 8590ec2 into main May 20, 2026
6 checks passed
@lamnhoan lamnhoan deleted the fix/dependabot-brace-expansion branch May 20, 2026 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants