* fix(#2765): bump brace-expansion to patched 1.1.18/5.0.9 (high-severity devDep advisory) npm audit fix (non-breaking) bumps the lockfile: brace-expansion 1.1.15→1.1.18 (eslint-nested via minimatch@3.x) and 5.0.6→5.0.9 (stryker-nested). Both 1.1.18 and 5.0.9 were published 2026-07-30 as the patch backports for GHSA-3jxr-9vmj-r5cp / GHSA-mh99-v99m-4gvg (range <=5.0.7). No overrides needed (in-range bump), no major bumps, no --force. Production (npm audit --omit=dev) unaffected (devDep only). Add a structural test pinning the installed versions so the bump can't silently regress. * chore(#2765): changeset fragment * fix(#2765): correct changeset issue ref + parse patch version as number (review findings) - changeset cited #2762 (typo) — fix to (#2765). - test compared v.split('.')[2] as a string (false-pass for 1.1.9) — parse all segments as Number. * chore(#2765): backfill changeset PR number (2888) --------- Co-authored-by: Test <test@example.com>
This commit is contained in:
5
.changeset/brave-orcas-rest.md
Normal file
5
.changeset/brave-orcas-rest.md
Normal file
@@ -0,0 +1,5 @@
|
||||
---
|
||||
type: Fixed
|
||||
pr: 2888
|
||||
---
|
||||
**Dev-dependency `brace-expansion` bumped to patched versions (1.1.18 / 5.0.9), resolving the high-severity DoS/OOM advisories** — the lockfile now pins the 2026-07-30 patch backports reachable via eslint and stryker. A non-breaking in-range bump (no overrides, no major bumps); production `npm audit --omit=dev` is unaffected (devDependency only). (#2765)
|
||||
26
package-lock.json
generated
26
package-lock.json
generated
@@ -815,9 +815,9 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/@eslint/config-array/node_modules/brace-expansion": {
|
||||
"version": "1.1.15",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz",
|
||||
"integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==",
|
||||
"version": "1.1.18",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz",
|
||||
"integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -913,9 +913,9 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/@eslint/eslintrc/node_modules/brace-expansion": {
|
||||
"version": "1.1.15",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz",
|
||||
"integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==",
|
||||
"version": "1.1.18",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz",
|
||||
"integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
@@ -2198,16 +2198,16 @@
|
||||
}
|
||||
},
|
||||
"node_modules/brace-expansion": {
|
||||
"version": "5.0.6",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.6.tgz",
|
||||
"integrity": "sha512-kLpxurY4Z4r9sgMsyG0Z9uzsBlgiU/EFKhj/h91/8yHu0edo7XuixOIH3VcJ8kkxs6/jPzoI6U9Vj3WqbMQ94g==",
|
||||
"version": "5.0.9",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz",
|
||||
"integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"balanced-match": "^4.0.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": "18 || 20 || >=22"
|
||||
"node": "20 || >=22"
|
||||
}
|
||||
},
|
||||
"node_modules/browserslist": {
|
||||
@@ -2887,9 +2887,9 @@
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/eslint/node_modules/brace-expansion": {
|
||||
"version": "1.1.15",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.15.tgz",
|
||||
"integrity": "sha512-EwOCDEex4quD37XhqM3omwtMoJjr//isUZz1JopUNWms+4Z2ViyM/k1YIRePpoVNnQhENnxtFjLaxNHrT7xIUg==",
|
||||
"version": "1.1.18",
|
||||
"resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz",
|
||||
"integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==",
|
||||
"dev": true,
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
|
||||
48
tests/issue-2765-brace-expansion-lockfile.test.cjs
Normal file
48
tests/issue-2765-brace-expansion-lockfile.test.cjs
Normal file
@@ -0,0 +1,48 @@
|
||||
// allow-test-rule: structural-implementation-guard (#2765)
|
||||
'use strict';
|
||||
|
||||
// Regression guard for #2765: the lockfile must pin the patched brace-expansion
|
||||
// versions (>=1.1.18 for the 1.x line, >=5.0.9 for the 5.x line) published 2026-07-30
|
||||
// to resolve the high-severity DoS/OOM advisories (GHSA-3jxr-9vmj-r5cp /
|
||||
// GHSA-mh99-v99m-4gvg, range <=5.0.7). This is a lockfile-only devDependency bump
|
||||
// (eslint/stryker → minimatch → brace-expansion); production (npm audit --omit=dev) is
|
||||
// unaffected. The test pins the installed versions so the bump can't silently regress.
|
||||
|
||||
const { test } = require('node:test');
|
||||
const assert = require('node:assert/strict');
|
||||
const { execFileSync } = require('node:child_process');
|
||||
const path = require('node:path');
|
||||
|
||||
const ROOT = path.join(__dirname, '..');
|
||||
|
||||
function npmLs(pkg) {
|
||||
// `npm ls <pkg> --json --all` lists every installed copy with its version. Collect
|
||||
// the version of every node whose key is `pkg` (not the parent packages).
|
||||
const out = execFileSync('npm', ['ls', pkg, '--json', '--all'], {
|
||||
cwd: ROOT, encoding: 'utf8', shell: true, stdio: ['ignore', 'pipe', 'ignore'],
|
||||
});
|
||||
const versions = [];
|
||||
const walk = (node) => {
|
||||
if (!node || !node.dependencies) return;
|
||||
for (const [k, v] of Object.entries(node.dependencies)) {
|
||||
if (k === pkg && v && v.version) versions.push(v.version);
|
||||
walk(v);
|
||||
}
|
||||
};
|
||||
walk(JSON.parse(out));
|
||||
return versions;
|
||||
}
|
||||
|
||||
test('all installed brace-expansion copies are patched (>=1.1.18 / >=5.0.9) — #2765', () => {
|
||||
const versions = npmLs('brace-expansion');
|
||||
assert.ok(versions.length > 0, 'brace-expansion must be installed (devDependency) to guard');
|
||||
for (const v of versions) {
|
||||
const [maj, min, pat] = v.split('.').map(Number);
|
||||
const ok = (maj === 1 && (min > 1 || (min === 1 && pat >= 18))) // 1.x >= 1.1.18
|
||||
|| (maj === 5 && (min > 0 || pat >= 9)) // 5.x >= 5.0.9
|
||||
|| (maj > 5); // >5.x
|
||||
assert.ok(ok,
|
||||
`brace-expansion@${v} is within the vulnerable range (<=5.0.7) — lockfile regressed the #2765 patch bump. ` +
|
||||
'Re-apply: npm audit fix (non-breaking) to bump to 1.1.18 / 5.0.9.');
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user