Skip to content

fix(FFESUPPORT-884): re-resolve brace-expansion to patched versions (Vanta 2026-07) - #286

Merged
aarsilv merged 2 commits into
mainfrom
aarsilv/ffesupport-884/vanta-supplement-2026-07
Jul 28, 2026
Merged

aarsilv merged 2 commits into
mainfrom
aarsilv/ffesupport-884/vanta-supplement-2026-07

Conversation

@aarsilv

@aarsilv aarsilv commented Jul 21, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated from Claude

Resolves the July 2026 Vanta/Dependabot supplement for js-client-sdk — FFESUPPORT-884.

What & why

One open advisory remained after the prior July sweep (#285): brace-expansion GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 (ReDoS), which affects >= 3.0.0, < 5.0.7 and < 1.1.16. It is a transitive, dev-only dependency (build/test tooling — no runtime, nothing in the published bundle).

Fix is a lockfile re-resolution only — no package.json or resolutions change:

Package Before After
brace-expansion (1.x line) 1.1.14 1.1.16
brace-expansion (5.x line) 5.0.5 5.0.7

(The ^2.0.2 line was also bumped 2.1.0 → 2.1.2 to clear the advisory's >= 2.0.0, < 2.1.2 range — a codex review caught that this third range was missed initially.)

How tests/CI protect this change

yarn typecheck clean and yarn test:unit green locally (153/153). CI runs the full build + unit suite; because the change is transitive dev tooling only, the build + test pass is the safety net.

Deferred / out of scope

None — this was the only open advisory for this repo.

Vanta/Dependabot advisory GHSA-3jxr-9vmj-r5cp (CVE-2026-13149). Re-resolve
the transitive dev-only brace-expansion to versions outside the vulnerable
ranges: 1.1.14 -> 1.1.16 and 5.0.5 -> 5.0.7. Lockfile-only; no package.json
or resolutions change.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@aarsilv
aarsilv requested a review from Copilot July 21, 2026 15:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@aarsilv

aarsilv commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Context from Claude: Final independent review via the local codex CLI (read-only) — no blocking issues found. codex confirmed all resolved brace-expansion versions are outside the advisory range (1.1.16 / 2.1.0 / 5.0.7), the diff changes only brace-expansion (no unintended dependency churn), and yarn check --integrity passes. (Non-blocking: a pre-existing, unrelated js-yaml resolution-range note that also exists on main.)

Codex review caught that GHSA-3jxr-9vmj-r5cp also affects `>= 2.0.0, < 2.1.2`
(not just the 1.x/5.x lines). Re-resolve the transitive dev-only 2.x copy
2.1.0 -> 2.1.2. Lockfile-only.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@aarsilv

aarsilv commented Jul 21, 2026

Copy link
Copy Markdown
Contributor Author

🤖 Context from Claude: Follow-up codex re-sweep after bumping the 2.x line — no blocking issues. All resolved brace-expansion copies are now patched (1.1.16 / 2.1.2 / 5.0.7), no 3.x/4.x copies, no unintended changes. (The 2.1.0→2.1.2 bump in a90fa96 closes the advisory's >= 2.0.0, < 2.1.2 range that the first pass missed.)

@aarsilv
aarsilv merged commit 78cba3e into main Jul 28, 2026
7 checks passed
@aarsilv
aarsilv deleted the aarsilv/ffesupport-884/vanta-supplement-2026-07 branch July 28, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants