Skip to content

chore: upgrade brace-expansion to ^1.1.21, ^2.1.7, ^5.0.12 to address CVE-2026-102276, CVE-2026-102277, CVE-2026-102278 - #1700

Open
claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/brace-expansion-2026-09
Open

claude[bot] wants to merge 2 commits into
mainfrom
cursor/cve/brace-expansion-2026-09

Conversation

@claude

@claude claude Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Fixes SOU-2385
Fixes SOU-2386
Fixes SOU-2387

Summary

Refreshes the yarn.lock entries for the transitive dependency brace-expansion:

Range (requested by minimatch) Before After
^1.1.13 (minimatch 3.1.5) 1.1.18 1.1.21
^2.0.3 (minimatch 9.0.9) 2.1.4 2.1.7
^5.0.5 (minimatch 10.2.4) 5.0.9 5.0.12

The existing caret ranges already admit the patched versions, so this is a lockfile-only refresh via yarn up -R brace-expansion. No package.json changes or resolutions overrides.

Note: the conventional cursor/cve/brace-expansion branch name is still held by a stale branch from closed/merged PRs (#1598, #1527), so this PR uses cursor/cve/brace-expansion-2026-09.

Verification

  • yarn why brace-expansion: resolves only to 1.1.21, 2.1.7, and 5.0.12.
  • yarn workspace @sourcebot/backend test: 309 passed.
  • yarn workspace @sourcebot/web test: 1506 passed.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only transitive dependency bump with no runtime logic changes; risk is limited to minimatch/glob pattern parsing behavior in patched versions.

Overview
Security dependency refresh for the transitive brace-expansion package (used via minimatch). The lockfile now resolves 1.1.21, 2.1.7, and 5.0.12 instead of 1.1.18, 2.1.4, and 5.0.9. Existing Yarn resolutions in package.json already permit these versions, so there is no application or config code change—only yarn.lock and an [Unreleased] changelog entry.

This addresses CVE-2026-102276, CVE-2026-102277, and CVE-2026-102278 (stack exhaustion, quadratic rescans on malformed brace patterns, and uncontrolled recursion in nested braces).

Reviewed by Cursor Bugbot for commit fafa48e. Bugbot is set up for automated code reviews on this repo. Configure here.

github-actions Bot and others added 2 commits September 30, 2026 14:24
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8bb0efa6-8d30-4e91-84b6-1e81c3fb09f1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

@claude[bot] your pull request is missing a changelog!

@github-actions

Copy link
Copy Markdown
Contributor

License Audit

❌ Audit failed to produce results. Check the workflow logs for details.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants