Skip to content

UID2-8025: preventive upgrade brace-expansion to 5.0.12 (CVE-2026-102278) - #1078

Merged
swibi-ttd merged 1 commit into
mainfrom
swi-UID2-8025-brace-expansion-5.0.12
Oct 6, 2026
Merged

swibi-ttd merged 1 commit into
mainfrom
swi-UID2-8025-brace-expansion-5.0.12

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Upgrades brace-expansion 5.0.8 → 5.0.12 (overrides in package.json) and regenerates the lockfile.

  • CVE-2026-102278 (HIGH, brace-expansion): Vulnerable code path is not reachable in this configuration.

5.0.12 rather than the advisory's 5.0.11, since 5.0.11 is affected by a later medium advisory.

The assessment is recorded on the ticket in the title.

🤖 Generated with Claude Code

)

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@swibi-ttd
swibi-ttd merged commit 1e230d0 into main Oct 6, 2026
1 of 2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants