chore(deps): update dependency brace-expansion@<2 to v2 [security] - #840
renovate[bot] wants to merge 1 commit into
Conversation
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit 7407b6a
💡 Verify your cache is correct by running tasks in a sandbox. Read docs ↗ ☁️ Nx Cloud last updated this comment at |
96253f9 to
e923cac
Compare
e923cac to
e553f2e
Compare
e553f2e to
a56e82f
Compare
a56e82f to
a5c223c
Compare
a5c223c to
d9bfaa9
Compare
d9bfaa9 to
ca7a638
Compare
ca7a638 to
2a610d4
Compare
@forgerock/davinci-client
@forgerock/device-client
@forgerock/journey-client
@forgerock/oidc-client
@forgerock/protect
@forgerock/recognize
@forgerock/sdk-types
@forgerock/sdk-utilities
@forgerock/iframe-manager
@forgerock/sdk-logger
@forgerock/sdk-oidc
@forgerock/sdk-request-middleware
@forgerock/storage
commit: |
|
Deployed 2009fea to https://ForgeRock.github.io/ping-javascript-sdk/pr-840/2009fea0b457975543feee8d63dc39d453f73bb0 branch gh-pages in ForgeRock/ping-javascript-sdk |
📦 Bundle Size Analysis📦 Bundle Size Analysis🆕 New Packages🆕 @forgerock/iframe-manager - 3.2 KB (new) 15 packages analyzed • Baseline from latest Legend🆕 New package ℹ️ How bundle sizes are calculated
🔄 Updated automatically on each push to this PR |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #840 +/- ##
===========================================
+ Coverage 18.07% 96.29% +78.22%
===========================================
Files 155 1 -154
Lines 24398 81 -24317
Branches 1203 17 -1186
===========================================
- Hits 4410 78 -4332
+ Misses 19988 3 -19985 🚀 New features to boost your workflow:
|
2a610d4 to
175a31f
Compare
c71d6d4 to
27c48aa
Compare
48cb50f to
cfff49e
Compare
cfff49e to
a9508c1
Compare
a9508c1 to
42ecb9f
Compare
There was a problem hiding this comment.
Important
At least one additional CI pipeline execution has run since the conclusion below was written and it may no longer be applicable.
Nx Cloud has identified a possible root cause for your failed CI:
We investigated the failing @forgerock/oidc-suites:e2e-ci--src/logout.spec.ts task and confirmed it is a pre-existing environment issue: the PingAM test server is not rendering the login UI in time, and the identical failure is also present on main. Our PR's only change — a brace-expansion security patch — has no logical connection to PingAM server availability or Playwright E2E behavior.
No code changes were suggested for this issue.
Trigger a rerun:
🎓 Learn more about Self-Healing CI on nx.dev
42ecb9f to
bcfc54f
Compare
bcfc54f to
7c80d9b
Compare
7c80d9b to
4317196
Compare
4317196 to
d21b9af
Compare
Interface Mapping Out of DateThe Drift reportTo fix, run: pnpm mapping:generateThen commit the updated |
d21b9af to
f96a839
Compare
f96a839 to
8e0257c
Compare
8e0257c to
7407b6a
Compare
7407b6a to
22cfb5a
Compare
This PR contains the following updates:
~1.1.15→~2.1.2brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
CVE-2026-13149 / GHSA-3jxr-9vmj-r5cp
More information
Details
Summary
brace-expansion's expand() exhibits exponential-time - O(2ⁿ) - behavior in the number of consecutive non-expanding {} groups. A short, all-ASCII input (~90 bytes/30 groups) blocks the calling thread for minutes; a slightly longer input hangs it effectively indefinitely. Because the dominant consumers run on Node's single-threaded event loop, one small input can fully stall a worker/process.
In
expand_,postis computed unconditionally at the top of the function, before the early-return branches that don't use it:For input like a{},{},…, the first {} is non-expanding, so control reaches the {a},b} rewrite branch - but
expand_has already recursed into post over the entire remaining tail, only to throw the result away.Each level therefore spawns two recursive expansions over essentially the same remaining work:
T(n) = 2·T(n−1) ⇒ O(2ⁿ).The max option does not mitigate this: max only bounds the output-building loops; neither the post recursion nor the rewrite recursion consults it.
Measured on 5.0.6:
Proof of concept
Impact
Any application that passes attacker-influenced strings to brace-expansion.expand() - directly or transitively via minimatch/glob brace patterns - can be driven into a multi-minute-to-indefinite CPU hang by a tiny request, denying service on that thread/process.
Remediation
Upgrade to a patched release. The fix:
Verified: the PoC drops from ~2 min to 0.55 ms, 5,000 groups complete in ~344 ms, and output is identical to 5.0.6 across a behavioral-equivalence suite (sequences, padding, $-prefix, a{},b}c, {},a}b, x{{a,b}}y, etc.). Post-fix complexity is ~O(n²) on this input class - acceptable for the security fix; a linear rewrite can be a non-urgent follow-up.
If immediate upgrade isn't possible, avoid passing untrusted input to expand() / glob brace patterns, or run such expansion under a timeout/worker.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/S:N/AU:Y/R:U/V:D/RE:M/U:AmberReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
juliangruber/brace-expansion (brace-expansion@<2)
v2.1.2Compare Source
v2.1.1Compare Source
c3a817cv2.1.0Compare Source
v2.0.3Compare Source
v2.0.2Compare Source
14f1d91ed7780a36603d5v2.0.1Compare Source
v2.0.0Compare Source
v1.1.21Compare Source
v1.1.20Compare Source
v1.1.19Compare Source
v1.1.18Compare Source
v1.1.17Compare Source
v1.1.16Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.