Skip to content

[HIGH] Bump brace-expansion patch releases - #58337

Open
OskarEichler wants to merge 1 commit into
react:mainfrom
OskarEichler:codex/security-brace-expansion
Open

OskarEichler wants to merge 1 commit into
react:mainfrom
OskarEichler:codex/security-brace-expansion

Conversation

@OskarEichler

@OskarEichler OskarEichler commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • update brace-expansion 1.1.11 to 1.1.18
  • update brace-expansion 2.0.2 to 2.1.4
  • update brace-expansion 5.0.6 to 5.0.9
  • retain every existing semver selector and change only the lockfile

Security impact

The locked releases are affected by denial-of-service issues including GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, and GHSA-rgw5-rvv9-x895. The updated patch/minor releases contain the upstream fixes for all affected major lines.

Test Plan

  • yarn install --frozen-lockfile --ignore-scripts
  • yarn why brace-expansion confirmed only 1.1.18, 2.1.4, and 5.0.9
  • yarn audit no longer reports brace-expansion advisories
  • yarn build
  • full yarn test --runInBand: 245 suites passed, 6,206 tests passed, 1 skipped, 1,721 snapshots passed
  • Jest retained a pre-existing open handle after reporting success and was stopped after completion
  • git diff --check

Changelog:

[INTERNAL] [SECURITY] - Bump brace-expansion patch releases.

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Sep 4, 2026
@facebook-github-tools facebook-github-tools Bot added the Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team. label Sep 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant