chore(deps): bump brace-expansion from 5.0.6 to 5.0.9 - #45
chore(deps): bump brace-expansion from 5.0.6 to 5.0.9#45dependabot[bot] wants to merge 1 commit into
Conversation
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
|
Superseded by #53 — please close this rather than merging it. This PR clears nothing, and I measured that rather than inferring it.
Pinning each version in the lockfile and running
Merging this would close the alert cosmetically while leaving the vulnerability in the tree — the worst of both outcomes, because it also removes the signal that would prompt a real fix. #53 goes to |
3645bea to
ed21a3a
Compare
|
PR author is in the excluded authors list. |
950dfdb to
8cd8724
Compare
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 5.0.6 to 5.0.9. - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v5.0.6...v5.0.9) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 5.0.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
8cd8724 to
b1c393a
Compare


Bumps brace-expansion from 5.0.6 to 5.0.9.
Commits
fbcf8ec5.0.9f6f3939test: cover dropping empties when only some prefixes are empty688a99eMerge commit from forkc66e5f9docs: make the maxLength example produce a non-empty result (#137)473d3e9Bump linkify-it from 5.0.1 to 5.0.2 (#128)96a63c05.0.8a1bd339Merge commit from fork592a36fBump tar from 7.5.16 to 7.5.20 (#127)bd14690Bump brace-expansion from 2.0.2 to 2.1.2 (#126)e729ba6Bump ws from 8.19.0 to 8.21.1 (#124)