Skip to content

fix(deps): bump brace-expansion to 5.0.8 (supersedes #45) - #53

Open
yakimoto wants to merge 1 commit into
mainfrom
fix/brace-expansion-5-0-8
Open

fix(deps): bump brace-expansion to 5.0.8 (supersedes #45)#53
yakimoto wants to merge 1 commit into
mainfrom
fix/brace-expansion-5-0-8

Conversation

@yakimoto

@yakimoto yakimoto commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Clears the brace-expansion HIGH (alert #3). Lockfile only — 4 lines.

brace-expansion  5.0.6 → 5.0.8    (dev scope, via eslint → @eslint/config-array → minimatch)

Supersedes #45, which bumps to 5.0.7 and clears nothing. Same fix as wave-av/mcp-server#67; the fleet-wide reasoning is in wave-av/claude-workstation#562.

Why #45 is a no-op — measured on this repo

There are two live brace-expansion advisories. The one on our alert is the older >= 3.0.0, < 5.0.7 (fix 5.0.7). The newer is GHSA-mh99-v99m-4gvg, range <= 5.0.7, patched only in 5.0.8 — so 5.0.7 lands inside it.

I pinned each version in the lockfile and ran the audit rather than reasoning about it:

brace-expansion total high still flagged?
5.0.6 (main) 3 2 yes
5.0.7 (what #45 ships) 3 2 yesrange: <=5.0.7
5.0.8 (this PR) 2 1 no

Why 5.0.8 is safe here specifically

This is the part that doesn't generalise. minimatch@3.1.5 does const expand = require('brace-expansion') and calls the result as a function; every patched release exports an object. On a minimatch@3 tree the "fix" throws TypeError: expand is not a function at runtime while npm audit reports clean — that's claude-workstation#554, where it also passed 195/195 tests.

This repo has exactly one tree and it's minimatch@10.2.5, confirmed by reading the ref rather than a working copy:

$ git show origin/main:package-lock.json | …
node_modules/brace-expansion -> 5.0.6
node_modules/minimatch       -> 10.2.5

minimatch@10 uses named exports, so the object shape is what it already expects. Verified by driving the consumer, since npm audit never loads the module:

minimatch export kind: object | callable: true
brace expansion match  : true      # minimatch('file2.js','file{1,2}.js')
negative control       : false     # minimatch('file3.js','file{1,2}.js')
nested braces          : true      # minimatch('a/b/c.ts','a/{b,d}/{c,e}.ts')
brace-expansion export : object EXPANSION_MAX,EXPANSION_MAX_LENGTH,expand

That last line is the exact shape that breaks minimatch@3 — and brace expansion still resolves correctly through minimatch@10.

One thing in the diff worth naming

5.0.8 narrows its own engines from "18 || 20 || >=22" to "20 || >=22" — it drops Node 18. That does not propagate to consumers of @wave-av/sdk: brace-expansion is "dev": true here, reached only through eslint, so it never enters the published dependency graph and our own engines: >=18.0.0 is unaffected. CI runs Node 20 (lint.yml) and 22 (release.yml, publish.yml), both satisfied.

Verification

CI can't run — Actions are refusing every job org-wide on an account-level billing lock (plan=free, locked=yes, re-confirmed live today). All local, on Node 22.14.0:

npm run lint        → clean (--max-warnings 0)
npm run type-check  → clean
npm run build       → success
npm test            → 90 tests / 2 files, 0 failed

Measurement caveat: this workstation exports NODE_ENV=production, which makes npm audit inherit omit=dev and silently hide dev-scope entries — including this one. Every figure above was taken with NODE_ENV=development set explicitly. Anyone re-checking needs to do the same or they'll see a different, wrong number.

Separate finding, not fixed here

While measuring the baseline I found a HIGH that Dependabot is not reporting: postcss@8.5.15, dev-only via tsup/vite, vulnerable to GHSA-r28c-9q8g-f849 (<= 8.5.17, fix 8.5.18, published 2026-07-24). It's in the GitHub Advisory Database, but this repo's alert list has only brace-expansion and esbuild. Filed separately rather than folded into this diff.


View with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is enabled.


Note

Low Risk
Dev-only lockfile dependency with no runtime or published-package impact; change is limited to tooling/eslint’s transitive tree.

Overview
Lockfile-only security bump: brace-expansion 5.0.6 → 5.0.8 (dev dependency via eslint@eslint/config-arrayminimatch@10). This clears the flagged HIGH advisory that 5.0.7 would not fully address (patched range requires 5.0.8).

The diff also updates brace-expansion’s declared engines from 18 || 20 || >=22 to 20 || >=22; that does not change the published @wave-av/sdk graph because the package stays dev-only.

Reviewed by Cursor Bugbot for commit 5c9f06f. Configure here.


Summary by cubic

Update brace-expansion to 5.0.8 in the lockfile to resolve a HIGH advisory. Supersedes #45; no runtime impact.

  • Dependencies
    • Dev-only path via eslint@eslint/config-arrayminimatch (not published).
    • Upstream engines now "20 || >=22"; safe given dev-only and our CI/runtime targets.

Written for commit 5c9f06f. Summary will update on new commits.

Review in cubic

@changeset-bot

changeset-bot Bot commented Jul 28, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 5c9f06f

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@cursor

cursor Bot commented Jul 28, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_20a4ede7-0bd3-41a7-9c78-b6122bc31efa)

@coderabbitai

coderabbitai Bot commented Jul 28, 2026

Copy link
Copy Markdown

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 3621cb3c-6009-4b5d-897a-b2534ac0c76a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/brace-expansion-5-0-8
✨ Simplify code
  • Create PR with simplified code
  • Commit simplified code in branch fix/brace-expansion-5-0-8

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant