fix(FFESUPPORT-884): re-resolve brace-expansion to patched versions (Vanta 2026-07) - #286
Conversation
Vanta/Dependabot advisory GHSA-3jxr-9vmj-r5cp (CVE-2026-13149). Re-resolve the transitive dev-only brace-expansion to versions outside the vulnerable ranges: 1.1.14 -> 1.1.16 and 5.0.5 -> 5.0.7. Lockfile-only; no package.json or resolutions change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
🤖 Context from Claude: Final independent review via the local codex CLI (read-only) — no blocking issues found. codex confirmed all resolved |
Codex review caught that GHSA-3jxr-9vmj-r5cp also affects `>= 2.0.0, < 2.1.2` (not just the 1.x/5.x lines). Re-resolve the transitive dev-only 2.x copy 2.1.0 -> 2.1.2. Lockfile-only. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
🤖 Context from Claude: Follow-up codex re-sweep after bumping the 2.x line — no blocking issues. All resolved brace-expansion copies are now patched (1.1.16 / 2.1.2 / 5.0.7), no 3.x/4.x copies, no unintended changes. (The 2.1.0→2.1.2 bump in a90fa96 closes the advisory's |
🤖 Generated from Claude
Resolves the July 2026 Vanta/Dependabot supplement for js-client-sdk — FFESUPPORT-884.
What & why
One open advisory remained after the prior July sweep (#285): brace-expansion GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 (ReDoS), which affects
>= 3.0.0, < 5.0.7and< 1.1.16. It is a transitive, dev-only dependency (build/test tooling — no runtime, nothing in the published bundle).Fix is a lockfile re-resolution only — no
package.jsonorresolutionschange:(The
^2.0.2line was also bumped 2.1.0 → 2.1.2 to clear the advisory's>= 2.0.0, < 2.1.2range — a codex review caught that this third range was missed initially.)How tests/CI protect this change
yarn typecheckclean andyarn test:unitgreen locally (153/153). CI runs the full build + unit suite; because the change is transitive dev tooling only, the build + test pass is the safety net.Deferred / out of scope
None — this was the only open advisory for this repo.