Repository navigation
fix: Bump brace-expansion from 1.1.13 to 1.1.21 - #3454
Conversation
|
🚀 Thanks for opening this pull request! We appreciate your effort in improving the project. Please let us know once your pull request is ready for review. Tip
Note Please respond to review comments from AI agents just like you would to comments from a human reviewer. Let the reviewer resolve their own comments, unless they have reviewed and accepted your commit, or agreed with your explanation for why the feedback was incorrect. Caution Pull requests must be written using an AI agent with human supervision. Pull requests written entirely by a human will likely be rejected, because of lower code quality, higher review effort and the higher risk of introducing bugs. Please note that AI review comments on this pull request alone do not satisfy this requirement. Our CI and AI review are safeguards, not development tools. If many issues are flagged, rethink your development approach. Invest more effort in planning and design rather than using review cycles to fix low-quality code. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 8 included reviews per hour; 4 remain after this review. 📝 WalkthroughWalkthroughThe lockfile updates root and nested ChangesDependency lockfile updates
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~4 minutes Merge Risk: ⚪ Minimal · up to The updated lockfile versions fit their dependency ranges, and the engine change remains compatible with supported runtimes. No actionable merge risk remains. Important Pre-merge checks failedPlease resolve all errors before merging. Addressing warnings is optional. ❌ Failed checks (1 inconclusive)
✅ Passed checks (6 passed)
Full details: Engage In Review FeedbackExplanation The supplied review metadata reports zero actionable findings for the current review. It explicitly does not establish whether earlier posted feedback comments exist or whether those comments were discussed, implemented, or retracted. The repository contains no review-discussion record that can resolve this gap. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
# [9.3.0-alpha.6](9.3.0-alpha.5...9.3.0-alpha.6) (2026-09-24) ### Bug Fixes * Bump brace-expansion from 1.1.13 to 1.1.21 ([#3454](#3454)) ([937fe17](937fe17))
|
🎉 This change has been released in version 9.3.0-alpha.6 |
Pull Request
Issue
Closes #3441
Approach
Bumps the transitive dependency
brace-expansionon all three version lines present in the lock file (lock file only):node_modules/brace-expansion(dev)minimatch@3.1.2(^1.1.7)minimatch,js-beautify(production);@jest/reporters,eslint-plugin-jest,jest-config,jest-runtime(dev)minimatch@9.x(^2.0.1)@typescript-eslint/typescript-estree(dev)minimatch@10.2.5(^5.0.5)The 2.x copies are production dependencies via
js-beautify→editorconfig→minimatch@9.0.1andjs-beautify→glob→minimatch@9.0.5. All new versions are within the ranges already declared by the parent packages. The copies bundled inside thenpmpackage (npm→brace-expansion@2.0.2,@semantic-release/npm→npm→brace-expansion@5.0.4) are bundled dependencies and are not changed.This resolves the open high-severity Dependabot alerts for
brace-expansion:{}groups (patched in 1.1.16, 2.1.2, 5.0.7)Changes
1.x line (1.1.13 → 1.1.21)
{ max }option to cap the number of expansions (opt-in, default unbounded)max(backport of 5.0.6, GHSA-jxxr-4gwj-5jf2)max100,000 results,maxLength4,000,000 characters)maxDepth, default 1,000){a},b}rescan is capped (maxRewrites, default 1,000)2.x line (2.0.3 → 2.1.7)
{ max }option to cap the number of expansions (opt-in, default unbounded). This is the minor-version change; the API change is additive (optional second argument)max(backport of 5.0.6, GHSA-jxxr-4gwj-5jf2)max100,000 results,maxLength4,000,000 characters)maxDepth, default 1,000){a},b}rescan is capped (maxRewrites, default 1,000)5.x line (5.0.5 → 5.0.12)
maxmaxLengthoption, default 4,000,000 characters); dropped Node 18 fromengines(now20 || >=22, which is compatible with this repository'sengines.nodeand CI matrix)maxDepth, default 1,000){a},b}rescan is capped (maxRewrites, default 1,000)Breaking Changes
None
Code Changes Required
None. The upgrade is a drop-in replacement. The export shape is unchanged: 1.x and 2.x still export the
expandfunction asmodule.exports, and 5.x still has the namedexpandexport. The only API change is a new optionaloptionsargument. The parent packages callexpand(pattern)(minimatch@3.1.2andminimatch@9.x) orexpand(pattern, { max })(minimatch@10.2.5), and both still work. The new default limits only affect pathological patterns (more than 100,000 results, 4,000,000 characters, or 1,000 nesting levels), far beyond any realistic glob pattern.Tasks
None. This PR changes the lock file only.
Summary by CodeRabbit