Repository navigation
fix(dev-1701): bump brace-expansion to 2.1.2 - #65
spur-vuln-author[bot] wants to merge 1 commit into
Conversation
|
Escalating: Gate 3 (diff equivalence) mechanically FAILed. gate3-check.sh: GATE3 FAIL target=brace-expansion manifest=pnpm-lock.yaml pr_version=? required=2.1.2 alerts=89,105 extra_files=1 state=open. Detail: the helper has no extraction rule for ecosystem=npm manifest basename=pnpm-lock.yaml, so it could not extract the new brace-expansion version from the diff, and flagged package.json as a file outside {manifest, lockfile} (which is actually the expected direct-dependency file for an npm/pnpm version bump). This looks like a tooling gap in gate3-check.sh (no pnpm-lock.yaml parser) rather than a real diff deviation, but per the review contract a mechanical Gate 3 FAIL is never re-derived or second-guessed by the reviewer. Required version per max open Dependabot alert(s) 89,105: 2.1.2. Not merged. A human must review this. This reviewer will not act on this PR again. [[spur-vuln-reviewer: escalated diff-mismatch-constructed]] |
Context
GHSA-3jxr-9vmj-r5cp:
brace-expansionis vulnerable to ReDoS (high severity), fixed at 2.1.2 (for the 2.x line). Transitive dependency (not declared in any package.json), resolved viapnpm-lock.yaml. No Dependabot PR exists for this finding, so this PR was constructed directly from the advisory'sfirst_patched_version.Test evidence
No Dependabot PR existed; constructed from first_patched_version 2.1.2. Added a
pnpm.overridesentry and regenerated the lockfile withpnpm install --lockfile-only. Two resolutions existed before (1.1.11 and 2.0.1); both now converge on2.1.7, satisfying >= 2.1.2. Companion-file scan (Dockerfiles,.nvmrc,go.mod, CI workflow YAML, etc. hardcoding1.1.11) found no hits.Risk
Medium — the override converges a previously-1.x-resolved consumer up to the 2.x line.
brace-expansion's public API (a single glob-brace-expansion function) has been stable across this major-version range, so functional risk is low, but flagging the major-line convergence for reviewer awareness. GHSA-3jxr-9vmj-r5cp / high severity; Tier 1 / 90-day SLA.