Skip to content

fix(security): update brace-expansion override to >=5.0.5#3030

Merged
marcusrbrown merged 1 commit intomainfrom
security/brace-expansion-5.0.5-override
Mar 28, 2026
Merged

fix(security): update brace-expansion override to >=5.0.5#3030
marcusrbrown merged 1 commit intomainfrom
security/brace-expansion-5.0.5-override

Conversation

@fro-bot
Copy link
Copy Markdown
Owner

@fro-bot fro-bot commented Mar 28, 2026

Summary

Addresses GHSA-v6vh-hvxj-x9wh (Medium severity) - brace-expansion package is vulnerable to Zero-step sequence causing process hang and memory exhaustion.

Security Advisory Details

  • Vulnerability: Zero-step sequence causes process hang and memory exhaustion
  • Affected versions: < 5.0.5
  • Fixed in: 5.0.5
  • Severity: Medium

Changes

  • Added `brace-expansion: >=5.0.5` to pnpm overrides in package.json

Dependency Chain

`brace-expansion` is a transitive dependency:

  • `@fro-bot/.github`
    • `@bfra.me/eslint-config` → `eslint` → `@eslint/config-array` → `minimatch` → `brace-expansion`

Testing

  • `pnpm check-format` passes
  • `pnpm check-types` passes
  • `pnpm lint` passes

Addresses GHSA-v6vh-hvxj-x9wh
- brace-expansion vulnerable to Zero-step sequence causing process hang and memory exhaustion
- brace-expansion is a transitive dependency via minimatch > eslint
- Override forces resolution to patched version >=5.0.5
@marcusrbrown marcusrbrown merged commit 47f8a4b into main Mar 28, 2026
6 checks passed
@marcusrbrown marcusrbrown deleted the security/brace-expansion-5.0.5-override branch March 28, 2026 10:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants