Skip to content

fix(deps): vuln brace-expansion (patch → 1.1.21) [package.json] - #845

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/1-1791183723
Draft

gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/1-1791183723

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 1 package upgraded (patch changes only)

Manifests changed:

  • package.json (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
brace-expansion 1.1.18 1.1.21 patch Transitive 4 HIGH, 2 MEDIUM

Security Details

🚨 Critical & High Severity (4 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion GHSA-6j4f-fj2g-mc7p HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 5.0.10 -
brace-expansion CVE-2026-102276 HIGH brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion 1.1.18 - -
brace-expansion GHSA-qhr7-859c-m2p7 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 5.0.11 -
brace-expansion CVE-2026-102278 HIGH brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion 1.1.18 - -
ℹ️ Other Vulnerabilities (2)
Package CVE Severity Summary Unsafe Version Fixed In Case
brace-expansion GHSA-q2hr-2g5m-vwhr MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 5.0.12 -
brace-expansion CVE-2026-102277 MODERATE brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service 1.1.18 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Pipelines

❌ Errors

Your PR has failed checks. Please review the issues below and take necessary action before merging.

🚦 1 Pipeline job failed

DataDog/datadog-lambda-js | publish layer sandbox (node24): [us-west-2]

View more details · View in GitLab

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: c11b70e | Docs | View more details | Give us feedback!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants