Update brace-expansion npm lockfile entries - #970
Raymond Zhao (rzhao271) with Copilot wants to merge 3 commits into
Conversation
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
|
Copilot Please first revert all dependency and lockfile changes made in this PR so the branch is restored to its original dependency state. Then regenerate the update from that clean baseline while observing the repository’s 7-day npm release hold: npm update brace-expansion --package-lock-only --min-release-age=7
npm install --min-release-age=7
npm testThe Component Governance dependency path containing
|
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Addressed in |
Component Governance flagged a vulnerable transitive
brace-expansionnpm dependency in the VS Code feed. This updates the resolved dependency path without overrides, resolutions, or force install flags.Dependency update
package-lock.jsonentries forbrace-expansionValidation
brace-expansionversions have no known GitHub advisories2.1.0version