Skip to content

Conversation

@mhassan1
Copy link

This PR bumps the vulnerable bundled dependency brace-expansion from 2.0.1 to 2.0.2 on the v10 branch (see GHSA-v6h2-p8h4-qcjw). This has already been addressed on the v11 branch in #8358.

There are other vulnerable instances of brace-expansion in the lockfile, but they are all related to development dependencies, so this PR doesn't bump them.

@mhassan1 mhassan1 requested a review from a team as a code owner June 13, 2025 02:49
@wraithgar
Copy link
Member

https://github.com/npm/cli/blob/latest/CONTRIBUTING.md#dependencies

@wraithgar wraithgar closed this Jun 13, 2025
@mhassan1
Copy link
Author

I've opened an issue about this, for tracking: #8366

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants