Skip to content

Updated dependencies#248

Merged
ijlee2 merged 3 commits intomainfrom
update-dependencies
Feb 4, 2026
Merged

Updated dependencies#248
ijlee2 merged 3 commits intomainfrom
update-dependencies

Conversation

@ijlee2
Copy link
Owner

@ijlee2 ijlee2 commented Feb 4, 2026

Background

Addresses a vulnerability marked critical (potentially affects the glob package).

@isaacs/brace-expansion@5.0.0 is vulnerable to a Denial of Service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated numeric brace ranges, the library attempts to eagerly generate every possible combination synchronously. Because the expansion grows exponentially, even a small input can consume excessive CPU and memory and may crash the Node.js process.

isaacs/brace-expansion@v5.0.0...v5.0.1

@ijlee2 ijlee2 added the enhance: dependency Issue asks for a new or updated dependency label Feb 4, 2026
@ijlee2 ijlee2 marked this pull request as ready for review February 4, 2026 08:27
@ijlee2 ijlee2 merged commit 07e4794 into main Feb 4, 2026
3 checks passed
@ijlee2 ijlee2 deleted the update-dependencies branch February 4, 2026 08:28
@ijlee2 ijlee2 mentioned this pull request Feb 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhance: dependency Issue asks for a new or updated dependency

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant