Skip to content

fix(deps): patch and deduplicate brace-expansion - #4355

Merged
martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/brace-expansion-security
Oct 2, 2026
Merged

martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:fix/brace-expansion-security

Conversation

@martinothamar-agent

@martinothamar-agent martinothamar-agent commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Update transitive brace-expansion dependencies to upstream releases fixing denial of service from comma parsing, deeply nested braces, and quadratic brace rewriting (CVE-2026-102276, CVE-2026-102277, and CVE-2026-102278).

Previous versions Patched version Dependabot alerts addressed
1.1.11 1.1.21 #375, #378, #381
2.0.1, 2.0.2 2.1.7 #374, #377, #380
5.0.4, 5.0.5 5.0.12 #373, #376, #379

Regenerated with yarn up -R brace-expansion --mode=update-lockfile. This changes only yarn.lock and deduplicates five vulnerable versions into three patched versions. Existing dependency ranges accept the updates; no overrides or parent dependency upgrades are needed. Different minimatch major versions still require separate brace-expansion major versions.

Dependency tracing found paths through dot-object's separate CLI and through test/lint/build tooling. Static inspection found no application code passing untrusted patterns to these packages. Upstream fixes are available, so patching is preferable to dismissing the alerts.

Related Issue(s)

Addresses Dependabot alerts #373, #374, #375, #376, #377, #378, #379, #380, and #381.

Upstream advisories: comma parsing, quadratic rewriting, and nested braces.

Verification/QA

Validated with Node 22.23.2 and the repository's Yarn 4.14.1:

  • yarn install --immutable --mode=skip-build passed (peer dependency warnings remain).

  • yarn dedupe brace-expansion --check passed: no further compatible deduplication available.

  • yarn gen, yarn exec tsc, and yarn exec tsc --project test/tsconfig.json passed.

  • yarn exec eslint . passed.

  • yarn build passed.

  • yarn exec jest --runInBand passed: 165 suites, 3,605 tests, and 2 snapshots; 1 suite and 61 tests skipped.

  • One-off probes of all five advisory attack shapes passed against each patched version, together with a normal brace-expansion smoke test. The 64 KB rewrite payload completed in approximately 16–17 ms on this machine.

  • git diff --check passed.

  • Manual functionality testing

    • No manual UI testing necessary for this transitive dependency update.
  • Automated tests

    • No new application tests needed; existing checks and advisory payload probes cover this update.
  • UU/WCAG

    • No accessibility testing necessary (no DOM/visual changes).
  • User documentation at altinn-studio-docs

    • No functionality has been changed/added, so no documentation is needed.
  • Support in Altinn Studio

    • This change does not require any changes to Altinn Studio.
  • Sprint board

    • Add to the appropriate project/sprint if needed.
  • Labels

    • Maintainer: add kind/dependencies and backport-ignore, matching the recent browserslist dependency update (chore(deps): patch and deduplicate browserslist #4351). GitHub denied this fork account permission to add labels; the label check will fail until they are added.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: d510ba9e-d0a2-4ae4-af6d-63b56a900fd8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@martinothamar martinothamar added kind/dependencies Pull requests that update a dependency file dependencies Pull requests that update a dependency file backport-ignore This PR is a new feature and should not be cherry-picked onto release branches labels Oct 1, 2026
@martinothamar
martinothamar merged commit 36726c2 into Altinn:main Oct 2, 2026
8 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-ignore This PR is a new feature and should not be cherry-picked onto release branches dependencies Pull requests that update a dependency file kind/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants