Skip to content

fix(deps): bump brace-expansion from 5.0.4 to 5.0.5#787

Merged
BYK merged 2 commits intomasterfrom
fix/bump-brace-expansion
Mar 27, 2026
Merged

fix(deps): bump brace-expansion from 5.0.4 to 5.0.5#787
BYK merged 2 commits intomasterfrom
fix/bump-brace-expansion

Conversation

@BYK
Copy link
Copy Markdown
Member

@BYK BYK commented Mar 27, 2026

Summary

Resolves Dependabot alert #142 (CVE-2026-33750): zero-step sequence
causes infinite loop and memory exhaustion in brace-expansion < 5.0.5.
@BYK BYK marked this pull request as ready for review March 27, 2026 13:37
@BYK BYK merged commit 507962a into master Mar 27, 2026
18 checks passed
@BYK BYK deleted the fix/bump-brace-expansion branch March 27, 2026 13:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant