fix(deps): patch and deduplicate brace-expansion - #4355
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Description
Update transitive
brace-expansiondependencies to upstream releases fixing denial of service from comma parsing, deeply nested braces, and quadratic brace rewriting (CVE-2026-102276, CVE-2026-102277, and CVE-2026-102278).Regenerated with
yarn up -R brace-expansion --mode=update-lockfile. This changes onlyyarn.lockand deduplicates five vulnerable versions into three patched versions. Existing dependency ranges accept the updates; no overrides or parent dependency upgrades are needed. Differentminimatchmajor versions still require separatebrace-expansionmajor versions.Dependency tracing found paths through
dot-object's separate CLI and through test/lint/build tooling. Static inspection found no application code passing untrusted patterns to these packages. Upstream fixes are available, so patching is preferable to dismissing the alerts.Related Issue(s)
Addresses Dependabot alerts #373, #374, #375, #376, #377, #378, #379, #380, and #381.
Upstream advisories: comma parsing, quadratic rewriting, and nested braces.
Verification/QA
Validated with Node 22.23.2 and the repository's Yarn 4.14.1:
yarn install --immutable --mode=skip-buildpassed (peer dependency warnings remain).yarn dedupe brace-expansion --checkpassed: no further compatible deduplication available.yarn gen,yarn exec tsc, andyarn exec tsc --project test/tsconfig.jsonpassed.yarn exec eslint .passed.yarn buildpassed.yarn exec jest --runInBandpassed: 165 suites, 3,605 tests, and 2 snapshots; 1 suite and 61 tests skipped.One-off probes of all five advisory attack shapes passed against each patched version, together with a normal brace-expansion smoke test. The 64 KB rewrite payload completed in approximately 16–17 ms on this machine.
git diff --checkpassed.Manual functionality testing
Automated tests
UU/WCAG
User documentation at altinn-studio-docs
Support in Altinn Studio
Sprint board
Labels
kind/dependenciesandbackport-ignore, matching the recent browserslist dependency update (chore(deps): patch and deduplicate browserslist #4351). GitHub denied this fork account permission to add labels; the label check will fail until they are added.