Skip to content

fix(deps): Bump brace-expansion to patched versions across the tree - #23112

Closed
Lms24 wants to merge 1 commit into
developfrom
fix/dependabot-alert-2060
Closed

fix(deps): Bump brace-expansion to patched versions across the tree#23112
Lms24 wants to merge 1 commit into
developfrom
fix/dependabot-alert-2060

Conversation

@Lms24

@Lms24 Lms24 commented Aug 6, 2026

Copy link
Copy Markdown
Member

Bumps brace-expansion to versions patched against two DoS advisories reachable via minimatch/glob: GHSA-3jxr-9vmj-r5cp (exponential-time {} expansion) and GHSA-rgw5-rvv9-x895 (unbounded intermediate arrays). Clearing both requires 1.1.18 / 2.1.4 / 5.0.9.

Spec Before After
^1.1.7 (×9) 1.1.11 1.1.18
^2.0.1, ^2.0.2 2.0.2 2.1.4
^5.0.5 (×7) 5.0.6 5.0.9
nx exact pin 5.0.6 5.0.9 (forced)

Every range above already accepted a patched release, so those three are a lockfile re-resolve. nx pins brace-expansion exactly and needed separate handling: bumping it 22.7.5 → 22.7.8 only reaches 5.0.8, which fixes the first advisory but not the second, and no nx release pins 5.0.9 or later. Hence the scoped resolution, mirroring the existing **/nx/minimatch entry. The nx bump is kept anyway because it also drops axios 1.16.0 (one high, two moderate advisories) plus form-data, hasown and tmp — that churn accounts for most of the lockfile diff.

Worth noting the alert is scoped development, but glob is a production dependency of @sentry/bundler-plugins and @sentry/react-router, so the ^5.0.5 row does ship to consumers.

Dependabot alert: https://github.com/getsentry/sentry-javascript/security/dependabot/2060

🤖 Generated with Claude Code

brace-expansion is vulnerable to two DoS advisories reachable through
minimatch/glob: GHSA-3jxr-9vmj-r5cp (exponential-time expansion of
consecutive non-expanding {} groups) and GHSA-rgw5-rvv9-x895 (unbounded
intermediate arrays). Fixing both requires 1.1.18 / 2.1.4 / 5.0.9.

Every semver range in the tree already accepted a patched release, so the
1.x, 2.x and 5.x lines are fixed by re-resolving the lockfile alone:

  ^1.1.7          1.1.11 -> 1.1.18
  ^2.0.1, ^2.0.2  2.0.2  -> 2.1.4
  ^5.0.5          5.0.6  -> 5.0.9

nx pins brace-expansion exactly, so its copy needs separate handling.
Bump nx 22.7.5 -> 22.7.8, which also drops axios 1.16.0 (one high and two
moderate advisories) along with form-data, hasown and tmp. That still
leaves nx on brace-expansion 5.0.8, which fixes only the first advisory,
and no nx release pins 5.0.9 or later -- so add a scoped resolution to
force it, mirroring the existing **/nx/minimatch entry.

Resolves GHSA-3jxr-9vmj-r5cp / CVE-2026-13149 and GHSA-rgw5-rvv9-x895.
Dependabot alert: https://github.com/getsentry/sentry-javascript/security/dependabot/2060

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Lms24
Lms24 force-pushed the fix/dependabot-alert-2060 branch from a85a705 to a1eb7fa Compare August 7, 2026 07:30
@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

size-limit report 📦

Path Size % Change Change
@sentry/browser 30.15 kB - -
@sentry/browser - with treeshaking flags 28.35 kB - -
@sentry/browser - with treeshaking flags tracing without tracing 26.66 kB - -
@sentry/browser (incl. Tracing) 47.56 kB - -
@sentry/browser (incl. Tracing + Span Streaming) 47.57 kB - -
@sentry/browser (incl. Tracing, Profiling) 52.31 kB - -
@sentry/browser (incl. Tracing, Replay) 86.93 kB - -
@sentry/browser (incl. Tracing, Replay) - with treeshaking flags 76.36 kB - -
@sentry/browser (incl. Tracing, Replay with Canvas) 91.66 kB - -
@sentry/browser (incl. Tracing, Replay, Feedback) 104.29 kB - -
@sentry/browser (incl. Feedback) 47.48 kB - -
@sentry/browser (incl. sendFeedback) 34.98 kB - -
@sentry/browser (incl. FeedbackAsync) 40.13 kB - -
@sentry/browser (incl. Metrics) 31.22 kB - -
@sentry/browser (incl. Logs) 31.44 kB - -
@sentry/browser (incl. Metrics & Logs) 32.13 kB - -
@sentry/react 31.95 kB - -
@sentry/react (incl. Tracing) 49.81 kB - -
@sentry/vue 35.25 kB - -
@sentry/vue (incl. Tracing) 49.57 kB - -
@sentry/svelte 30.17 kB - -
CDN Bundle 32.16 kB - -
CDN Bundle (incl. Tracing) 47.83 kB - -
CDN Bundle (incl. Logs, Metrics) 33.7 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) 49.21 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) 73.03 kB - -
CDN Bundle (incl. Tracing, Replay) 85.47 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) 86.79 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) 91.29 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) 92.61 kB - -
CDN Bundle - uncompressed 95.33 kB - -
CDN Bundle (incl. Tracing) - uncompressed 142.84 kB - -
CDN Bundle (incl. Logs, Metrics) - uncompressed 99.96 kB - -
CDN Bundle (incl. Tracing, Logs, Metrics) - uncompressed 146.82 kB - -
CDN Bundle (incl. Replay, Logs, Metrics) - uncompressed 224.66 kB - -
CDN Bundle (incl. Tracing, Replay) - uncompressed 262.09 kB - -
CDN Bundle (incl. Tracing, Replay, Logs, Metrics) - uncompressed 266.06 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback) - uncompressed 275.8 kB - -
CDN Bundle (incl. Tracing, Replay, Feedback, Logs, Metrics) - uncompressed 279.75 kB - -
@sentry/nextjs (client) 52.39 kB - -
@sentry/sveltekit (client) 48.01 kB - -
@sentry/core/server 65.58 kB - -
@sentry/core/browser 51.82 kB - -
@sentry/node 119.28 kB - -
@sentry/node/import (ESM hook with diagnostics-channel injection) 0 B added added
@sentry/node - without tracing 83.3 kB - -
@sentry/aws-serverless 92.61 kB - -
@sentry/cloudflare (withSentry) - minified 214.16 kB - -
@sentry/cloudflare (withSentry) 528.83 kB - -

View base workflow run

@Lms24 Lms24 closed this Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant