chore(deps): update dependency brace-expansion to v5.0.12 [security] #62

Open
renovate-bot wants to merge 1 commit from renovate/npm-brace-expansion-vulnerability into main
Member

This PR contains the following updates:

Package Change Age Confidence
brace-expansion 5.0.9 → 5.0.12 age confidence

brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion

CVE-2026-102276 / GHSA-6j4f-fj2g-mc7p

More information

Details

Summary

parseCommaParts() can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string.

This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made expand_() iterative and documented a constant-stack-depth guarantee, but parseCommaParts() was left recursive, so the guarantee only held for one of the two parsing paths.

Vector 1 - unbounded recursion on post

parseCommaParts() recursed on the remainder of the string once per brace group:

const postParts = parseCommaParts(post)   // unbounded

A brace group containing many comma-separated groups drives one recursion level per group:

expand('{' + '{a},'.repeat(7000) + 'b}')
// RangeError: Maximum call stack size exceeded

About 7,300 repetitions - roughly 29 KB of input - is enough on Node 24; roughly 6,300 (25 KB) on Node 18. The threshold is identical on every affected release line.

Vector 2 - push.apply with an unbounded array

Even with the recursion removed, parseCommaParts() spread whole arrays into an argument list:

p.push.apply(p, postParts)
parts.push.apply(parts, p)

Function.prototype.apply places one argument per element on the stack, so a single large array overflows it. This needs no recursion depth at all - the following reaches a recursion depth of exactly 1:

expand('{{x},' + 'a,'.repeat(125000) + 'b}')
// RangeError: Maximum call stack size exceeded

Threshold is about 124,300 repetitions (~249 KB). This vector was not part of the original report; it was found while verifying the fix. A patch that only de-recurses but keeps push.apply leaves a working denial of service behind.

Why max and maxLength do not help

Both crashes happen during parsing, before any expansion. The payloads produce one result per group, so output size grows linearly with input and is never the limiter. expand(payload, { max: 1, maxLength: 1 }) still overflows.

Impact

Any application that passes an untrusted string to expand() - directly, or through minimatch / glob where it is a user-supplied glob pattern - can be crashed. In Node, a RangeError that the application does not catch terminates the process, so a server that globs user input is exposed to remote unauthenticated denial of service.

minimatch's own MAX_PATTERN_LENGTH cap (65,536) does not help against vector 1: the overflow threshold sits well below it. Confirmed on minimatch 10.2.6 - a 64,003-byte pattern passes the length check and overflows both minimatch.braceExpand() and new minimatch.Minimatch().

This is an availability-only issue. No code execution and no data exposure.

Not a regression

5.0.8 and 5.0.9 overflow at the same repetition count, so the gap predates the recent advisories; those fixes simply did not reach it. Verified affected on 1.1.18, 2.1.4, 3.0.6, 5.0.8 and 5.0.9, all at an identical threshold.

Patch

parseCommaParts() is rewritten as a loop that carries the partial part across chunks, and every array append uses an element-by-element loop rather than push.apply. The redundant if (!str) return [''] guard is dropped - the loop returns [''] for the empty string on its own.

Equivalence of the old and new implementations was checked by differential testing: exhaustive over every string of {, }, ,, a up to length 7 plus 300,000 random inputs - 322,000 cases, zero mismatches.

Severity note

Scored 7.5 High under CVSS 3.1 for consistency with the other availability advisories on this package (GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895), which use the same vector. The reporter self-assessed 6.9 Medium under CVSS 4.0 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N).

Credit

Reported by baeseungwon1010, with a working proof of concept and a proposed patch. Vector 2 was identified during maintainer verification.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion

CVE-2026-102278 / GHSA-qhr7-859c-m2p7

More information

Details

Summary

expand_() recurses once per level of brace nesting. Deeply nested input exhausts the native stack and crashes the process.

This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the tail iterative (recursion on m.post, driven by how many groups are chained). Nesting depth drives a different recursion that the tail fix never touched, so the documented constant-stack-depth guarantee only ever covered chained input, not nested input.

It is also distinct from GHSA-6j4f-fj2g-mc7p, which fixed recursion in parseCommaParts(). Both payloads below still crash with that fix applied.

Two recursion sites

Comma members. Each alternative of a brace set is expanded by a recursive call, so nesting a set inside every alternative recurses once per level:

expand('{a,'.repeat(4000) + 'z' + '}'.repeat(4000))
// RangeError: Maximum call stack size exceeded

Crashes at depth 3,907 - about 15.6 KB of input.

Single set. A brace set whose body parses to a single part is expanded by a recursive call before being re-wrapped (x{{a,b}}y -> x{a}y x{b}y), which recurses once per nesting level:

expand('{'.repeat(3200) + 'a,b' + '}'.repeat(3200))
// RangeError: Maximum call stack size exceeded

Crashes at depth 3,125 - about 6.25 KB of input. This is the cheapest stack-exhaustion payload known against this package: roughly a quarter the input of GHSA-6j4f-fj2g-mc7p (29 KB), and about a tenth of minimatch's MAX_PATTERN_LENGTH (65,536).

Why max and maxLength do not help

Both crashes happen while recursing into sub-expansions, before the result set grows. The payloads produce almost no output - the single-set case yields 2 results - so neither bound is ever the limiter. expand(payload, { max: 1, maxLength: 1 }) still overflows.

Impact

Any application passing an untrusted string to expand(), directly or through minimatch / glob as a user-supplied glob pattern, can be crashed. In Node a RangeError the application does not catch terminates the process, so a server globbing user input is exposed to remote unauthenticated denial of service.

Availability only. No code execution, no data exposure.

Affected versions

Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, at near-identical depths on every line (single set: 3,125 on all four; comma members: 3,907-4,102). Not a regression from any recent fix - the gap predates them.

Patch

A maxDepth bound (default EXPANSION_MAX_DEPTH) is threaded through expand_(). Past the cap a group is treated as non-expanding and returned literally, which is how the parser already handles a group that cannot expand. This matches the existing max / maxLength caps, which truncate rather than throw, so expand() continues never to throw on any input.

The default sits far above any realistic nesting depth and well below the crash threshold.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


brace-expansion: Quadratic-time expansion of the {a},b} rewrite causes CPU denial of service

CVE-2026-102277 / GHSA-q2hr-2g5m-vwhr

More information

Details

Summary

Expanding {a},b}-shaped input takes time quadratic in the number of literal } characters, blocking the event loop.

Bash preserves a quirk where a brace group followed by a comma set still expands ({a},b}). The parser implements this by rewriting the string and restarting the scan. Each pass absorbs exactly one } and re-scans from the beginning, so n trailing braces cost n full passes.

Reproduction
const build = n => '{a}' + '}'.repeat(n) + ',z}'

for (const n of [8000, 16000, 32000, 64000, 128000]) {
  const t = Date.now()
  expand(build(n))
  console.log(n, Date.now() - t + 'ms')
}
n input time results
8,000 8 KB 110 ms 2
16,000 16 KB 446 ms 2
32,000 32 KB 1.7 s 2
64,000 64 KB 6.9 s 2
128,000 128 KB 27.7 s 2

ms/n^2 is flat at ~1.7 and each doubling of n costs exactly 4.0x - quadratic. 128 KB of input blocks the event loop for nearly half a minute to produce two results.

Mechanism

Instrumenting the rewrite branch confirms it runs exactly n + 1 times, once per literal }, each re-scanning the whole string.

There is a second multiplier. The rewrite replaces the group's closing } with the internal escClose sentinel, which is '\0CLOSE' + Math.random() + '\0' - about 25 characters. The working string therefore grows by ~25 characters on every pass:

n input length final string length
1,000 1,006 26,006
8,000 8,006 208,006

So the input is inflated roughly 26x, and that factor multiplies both the quadratic constant and peak memory. This makes it partly a memory-pressure issue as well as a CPU one.

Why max and maxLength do not help

The cost is in parsing, before the result set exists. The payload yields 2 results regardless of size, so neither bound is ever reached.

Impact

An application passing an untrusted pattern to expand(), directly or through minimatch / glob, can have its event loop blocked for tens of seconds by a payload well under minimatch's 65,536-character cap. For a single-threaded Node server that is a full stall, not just a slow request.

Degraded availability rather than a crash - the process recovers once the expansion completes.

Affected versions

Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, all within a few percent of each other (~460-490 ms at n=16,000).

Patch

The rewrite loop gets an iteration bound. Past the cap the remaining string is treated as non-expanding and returned literally, consistent with the existing max / maxLength caps, which truncate rather than throw.

Note this bounds the number of passes, not the cost of each: worst-case work remains proportional to cap x input length. The cap is set low enough that the residual is bounded in practice, and far above what any realistic {a},b} input needs.

Severity note

Scored 5.3 Medium (A:L) for consistency with GHSA-3jxr-9vmj-r5cp, the other algorithmic-complexity advisory on this package (CWE-407), which uses the same vector. The stack-exhaustion advisories on this package score A:H because they crash the process outright; this one stalls it.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).

❗ Important

Release Notes retrieval for this PR were skipped because no github.com credentials were available.
If you are self-hosted, please see this instruction.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [brace-expansion](https://github.com/juliangruber/brace-expansion) | [`5.0.9` → `5.0.12`](https://renovatebot.com/diffs/npm/brace-expansion/5.0.9/5.0.12) | ![age](https://developer.mend.io/api/mc/badges/age/npm/brace-expansion/5.0.12?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/brace-expansion/5.0.9/5.0.12?slim=true) | --- ### brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion [CVE-2026-102276](https://nvd.nist.gov/vuln/detail/CVE-2026-102276) / [GHSA-6j4f-fj2g-mc7p](https://github.com/advisories/GHSA-6j4f-fj2g-mc7p) <details> <summary>More information</summary> #### Details ##### Summary `parseCommaParts()` can exhaust the native stack and crash the process. There are two distinct ways to trigger it, both reachable from a single untrusted pattern string. This is the parsing-side counterpart to CVE-2026-14257 / GHSA-mh99-v99m-4gvg. That fix made `expand_()` iterative and documented a constant-stack-depth guarantee, but `parseCommaParts()` was left recursive, so the guarantee only held for one of the two parsing paths. ##### Vector 1 - unbounded recursion on `post` `parseCommaParts()` recursed on the remainder of the string once per brace group: ```js const postParts = parseCommaParts(post) // unbounded ``` A brace group containing many comma-separated groups drives one recursion level per group: ```js expand('{' + '{a},'.repeat(7000) + 'b}') // RangeError: Maximum call stack size exceeded ``` About 7,300 repetitions - roughly 29 KB of input - is enough on Node 24; roughly 6,300 (25 KB) on Node 18. The threshold is identical on every affected release line. ##### Vector 2 - `push.apply` with an unbounded array Even with the recursion removed, `parseCommaParts()` spread whole arrays into an argument list: ```js p.push.apply(p, postParts) parts.push.apply(parts, p) ``` `Function.prototype.apply` places one argument per element on the stack, so a single large array overflows it. This needs **no recursion depth at all** - the following reaches a recursion depth of exactly 1: ```js expand('{{x},' + 'a,'.repeat(125000) + 'b}') // RangeError: Maximum call stack size exceeded ``` Threshold is about 124,300 repetitions (~249 KB). This vector was not part of the original report; it was found while verifying the fix. A patch that only de-recurses but keeps `push.apply` leaves a working denial of service behind. ##### Why `max` and `maxLength` do not help Both crashes happen during **parsing**, before any expansion. The payloads produce one result per group, so output size grows linearly with input and is never the limiter. `expand(payload, { max: 1, maxLength: 1 })` still overflows. ##### Impact Any application that passes an untrusted string to `expand()` - directly, or through `minimatch` / `glob` where it is a user-supplied glob pattern - can be crashed. In Node, a `RangeError` that the application does not catch terminates the process, so a server that globs user input is exposed to remote unauthenticated denial of service. `minimatch`'s own `MAX_PATTERN_LENGTH` cap (65,536) does not help against vector 1: the overflow threshold sits well below it. Confirmed on minimatch 10.2.6 - a 64,003-byte pattern passes the length check and overflows both `minimatch.braceExpand()` and `new minimatch.Minimatch()`. This is an availability-only issue. No code execution and no data exposure. ##### Not a regression 5.0.8 and 5.0.9 overflow at the same repetition count, so the gap predates the recent advisories; those fixes simply did not reach it. Verified affected on 1.1.18, 2.1.4, 3.0.6, 5.0.8 and 5.0.9, all at an identical threshold. ##### Patch `parseCommaParts()` is rewritten as a loop that carries the partial part across chunks, and every array append uses an element-by-element loop rather than `push.apply`. The redundant `if (!str) return ['']` guard is dropped - the loop returns `['']` for the empty string on its own. Equivalence of the old and new implementations was checked by differential testing: exhaustive over every string of `{`, `}`, `,`, `a` up to length 7 plus 300,000 random inputs - 322,000 cases, zero mismatches. ##### Severity note Scored 7.5 High under CVSS 3.1 for consistency with the other availability advisories on this package (GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895), which use the same vector. The reporter self-assessed 6.9 Medium under CVSS 4.0 (`CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N`). ##### Credit Reported by baeseungwon1010, with a working proof of concept and a proposed patch. Vector 2 was identified during maintainer verification. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p](https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p) - [https://nvd.nist.gov/vuln/detail/CVE-2026-102276](https://nvd.nist.gov/vuln/detail/CVE-2026-102276) - [https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc](https://github.com/juliangruber/brace-expansion/commit/0bcbfc0a5928c3073d48f42999d1ce4fc1c42fbc) - [https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c](https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c) - [https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc](https://github.com/juliangruber/brace-expansion/commit/5171e681c0922b7ae8bfaf9a331e309107be6edc) - [https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3](https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3) - [https://github.com/juliangruber/brace-expansion](https://github.com/juliangruber/brace-expansion) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-6j4f-fj2g-mc7p) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion [CVE-2026-102278](https://nvd.nist.gov/vuln/detail/CVE-2026-102278) / [GHSA-qhr7-859c-m2p7](https://github.com/advisories/GHSA-qhr7-859c-m2p7) <details> <summary>More information</summary> #### Details ##### Summary `expand_()` recurses once per level of brace *nesting*. Deeply nested input exhausts the native stack and crashes the process. This is distinct from CVE-2026-14257 / GHSA-mh99-v99m-4gvg, which made the *tail* iterative (recursion on `m.post`, driven by how many groups are chained). Nesting depth drives a different recursion that the tail fix never touched, so the documented constant-stack-depth guarantee only ever covered chained input, not nested input. It is also distinct from GHSA-6j4f-fj2g-mc7p, which fixed recursion in `parseCommaParts()`. Both payloads below still crash with that fix applied. ##### Two recursion sites **Comma members.** Each alternative of a brace set is expanded by a recursive call, so nesting a set inside every alternative recurses once per level: ```js expand('{a,'.repeat(4000) + 'z' + '}'.repeat(4000)) // RangeError: Maximum call stack size exceeded ``` Crashes at depth 3,907 - about **15.6 KB** of input. **Single set.** A brace set whose body parses to a single part is expanded by a recursive call before being re-wrapped (`x{{a,b}}y` -> `x{a}y x{b}y`), which recurses once per nesting level: ```js expand('{'.repeat(3200) + 'a,b' + '}'.repeat(3200)) // RangeError: Maximum call stack size exceeded ``` Crashes at depth 3,125 - about **6.25 KB** of input. This is the cheapest stack-exhaustion payload known against this package: roughly a quarter the input of GHSA-6j4f-fj2g-mc7p (29 KB), and about a tenth of minimatch's `MAX_PATTERN_LENGTH` (65,536). ##### Why `max` and `maxLength` do not help Both crashes happen while recursing into sub-expansions, before the result set grows. The payloads produce almost no output - the single-set case yields 2 results - so neither bound is ever the limiter. `expand(payload, { max: 1, maxLength: 1 })` still overflows. ##### Impact Any application passing an untrusted string to `expand()`, directly or through `minimatch` / `glob` as a user-supplied glob pattern, can be crashed. In Node a `RangeError` the application does not catch terminates the process, so a server globbing user input is exposed to remote unauthenticated denial of service. Availability only. No code execution, no data exposure. ##### Affected versions Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, at near-identical depths on every line (single set: 3,125 on all four; comma members: 3,907-4,102). Not a regression from any recent fix - the gap predates them. ##### Patch A `maxDepth` bound (default `EXPANSION_MAX_DEPTH`) is threaded through `expand_()`. Past the cap a group is treated as non-expanding and returned literally, which is how the parser already handles a group that cannot expand. This matches the existing `max` / `maxLength` caps, which truncate rather than throw, so `expand()` continues never to throw on any input. The default sits far above any realistic nesting depth and well below the crash threshold. #### Severity - CVSS Score: 7.5 / 10 (High) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` #### References - [https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7](https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7) - [https://nvd.nist.gov/vuln/detail/CVE-2026-102278](https://nvd.nist.gov/vuln/detail/CVE-2026-102278) - [https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b](https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b) - [https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c](https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c) - [https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db](https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db) - [https://github.com/juliangruber/brace-expansion](https://github.com/juliangruber/brace-expansion) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-qhr7-859c-m2p7) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service [CVE-2026-102277](https://nvd.nist.gov/vuln/detail/CVE-2026-102277) / [GHSA-q2hr-2g5m-vwhr](https://github.com/advisories/GHSA-q2hr-2g5m-vwhr) <details> <summary>More information</summary> #### Details ##### Summary Expanding `{a},b}`-shaped input takes time quadratic in the number of literal `}` characters, blocking the event loop. Bash preserves a quirk where a brace group followed by a comma set still expands (`{a},b}`). The parser implements this by rewriting the string and restarting the scan. Each pass absorbs exactly one `}` and re-scans from the beginning, so `n` trailing braces cost `n` full passes. ##### Reproduction ```js const build = n => '{a}' + '}'.repeat(n) + ',z}' for (const n of [8000, 16000, 32000, 64000, 128000]) { const t = Date.now() expand(build(n)) console.log(n, Date.now() - t + 'ms') } ``` | n | input | time | results | |---|---|---|---| | 8,000 | 8 KB | 110 ms | 2 | | 16,000 | 16 KB | 446 ms | 2 | | 32,000 | 32 KB | 1.7 s | 2 | | 64,000 | 64 KB | 6.9 s | 2 | | 128,000 | 128 KB | **27.7 s** | 2 | `ms/n^2` is flat at ~1.7 and each doubling of `n` costs exactly 4.0x - quadratic. 128 KB of input blocks the event loop for nearly half a minute to produce two results. ##### Mechanism Instrumenting the rewrite branch confirms it runs exactly `n + 1` times, once per literal `}`, each re-scanning the whole string. There is a second multiplier. The rewrite replaces the group's closing `}` with the internal `escClose` sentinel, which is `'\0CLOSE' + Math.random() + '\0'` - about 25 characters. The working string therefore *grows* by ~25 characters on every pass: | n | input length | final string length | |---|---|---| | 1,000 | 1,006 | 26,006 | | 8,000 | 8,006 | 208,006 | So the input is inflated roughly 26x, and that factor multiplies both the quadratic constant and peak memory. This makes it partly a memory-pressure issue as well as a CPU one. ##### Why `max` and `maxLength` do not help The cost is in parsing, before the result set exists. The payload yields 2 results regardless of size, so neither bound is ever reached. ##### Impact An application passing an untrusted pattern to `expand()`, directly or through `minimatch` / `glob`, can have its event loop blocked for tens of seconds by a payload well under minimatch's 65,536-character cap. For a single-threaded Node server that is a full stall, not just a slow request. Degraded availability rather than a crash - the process recovers once the expansion completes. ##### Affected versions Verified affected on 1.1.18, 2.1.4, 3.0.6 and 5.0.9, all within a few percent of each other (~460-490 ms at n=16,000). ##### Patch The rewrite loop gets an iteration bound. Past the cap the remaining string is treated as non-expanding and returned literally, consistent with the existing `max` / `maxLength` caps, which truncate rather than throw. Note this bounds the number of passes, not the cost of each: worst-case work remains proportional to `cap x input length`. The cap is set low enough that the residual is bounded in practice, and far above what any realistic `{a},b}` input needs. ##### Severity note Scored 5.3 Medium (`A:L`) for consistency with GHSA-3jxr-9vmj-r5cp, the other algorithmic-complexity advisory on this package (CWE-407), which uses the same vector. The stack-exhaustion advisories on this package score `A:H` because they crash the process outright; this one stalls it. #### Severity - CVSS Score: 5.3 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L` #### References - [https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr](https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr) - [https://nvd.nist.gov/vuln/detail/CVE-2026-102277](https://nvd.nist.gov/vuln/detail/CVE-2026-102277) - [https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96](https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96) - [https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22](https://github.com/juliangruber/brace-expansion/commit/bdff773f98e5988616b7039cc9b508df5d640b22) - [https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364](https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364) - [https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e](https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e) - [https://github.com/juliangruber/brace-expansion](https://github.com/juliangruber/brace-expansion) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-q2hr-2g5m-vwhr) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> > ❗ **Important** > > Release Notes retrieval for this PR were skipped because no github.com credentials were available. > If you are self-hosted, please see [this instruction](https://github.com/renovatebot/renovate/blob/master/docs/usage/examples/self-hosting.md#githubcom-token-for-release-notes). --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ1cGRhdGVkSW5WZXIiOiI0NC4xMTUuMTMiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInNlY3VyaXR5L3Z1bG4iXX0=-->
chore(deps): update dependency brace-expansion to v5.0.12 [security]
Some checks failed
scan / trivy-fs (pull_request) Failing after 1m20s
ai-review / review (pull_request) Successful in 1m26s
baseline-security / baseline (pull_request) Failing after 1m48s
scan / trivy-fs (push) Failing after 1m15s
baseline-security / baseline (push) Failing after 2m2s
247bd2a8fb

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
GHSA-j95f-988m-3j2f (HIGH) @tiptap/core 3.28.0 → 3.30.5 no fix PR yet — npm update core --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:247bd2a8fbc90c795b1d4e2df280163002461312 --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | GHSA-j95f-988m-3j2f (HIGH) | `@tiptap/core` | 3.28.0 → 3.30.5 | no fix PR yet — `npm update core --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
ai-review-bot left a comment

AI review · advisory

Verdict: nothing found — 2 of 4 reviewers answered and none found anything that needs fixing; the rest gave no usable review (see the debate digest).

⚑ panel: Gemma 4 31B · Laguna S 2.1 (no review: GPT-OSS 120B, Devstral 2 123B) — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 2 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • Gemma 4 31B (0 findings, confidence 1.0 · thought 3.8k + wrote 68 of 16.0k tokens · 96 s): The changes correctly update the brace-expansion dependency to a secure version via npm overrides and synchronize the lockfile versions with the project manifests.
  • Laguna S 2.1 (0 findings, confidence 0.96 · wrote 96 of 65.5k tokens · 4 s): PR is a mechanical, correct security bump of brace-expansion from 5.0.9 to 5.0.12 — both the package-lock.json entry and the package.json override are consistent, the integrity hash and version match,
  • GPT-OSS 120B — no review: the call failed.
  • Devstral 2 123B — no review: the call failed.

Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20260930051230-ba6bd7 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20260930051230-ba6bd7.

### AI review · advisory <!-- tti-rv:rv-20260930051230-ba6bd7: --> **Verdict: nothing found** — 2 of 4 reviewers answered and none found anything that needs fixing; the rest gave no usable review (see the debate digest). <sub>⚑ panel: Gemma 4 31B · Laguna S 2.1 (no review: GPT-OSS 120B, Devstral 2 123B) — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 2 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **Gemma 4 31B** (0 findings, confidence 1.0 · thought 3.8k + wrote 68 of 16.0k tokens · 96 s): The changes correctly update the brace-expansion dependency to a secure version via npm overrides and synchronize the lockfile versions with the project manifests. - **Laguna S 2.1** (0 findings, confidence 0.96 · wrote 96 of 65.5k tokens · 4 s): PR is a mechanical, correct security bump of brace-expansion from 5.0.9 to 5.0.12 — both the package-lock.json entry and the package.json override are consistent, the integrity hash and version match, - **GPT-OSS 120B** — no review: the call failed. - **Devstral 2 123B** — no review: the call failed. **Synthesis** — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20260930051230-ba6bd7` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20260930051230-ba6bd7`.</sub>
renovate-bot force-pushed renovate/npm-brace-expansion-vulnerability from 247bd2a8fb
Some checks failed
scan / trivy-fs (pull_request) Failing after 1m20s
ai-review / review (pull_request) Successful in 1m26s
baseline-security / baseline (pull_request) Failing after 1m48s
scan / trivy-fs (push) Failing after 1m15s
baseline-security / baseline (push) Failing after 2m2s
to 5f048412d2
Some checks failed
baseline-security / baseline (push) Failing after 2m21s
scan / trivy-fs (push) Failing after 2m22s
ai-review / review (pull_request) Successful in 1m54s
baseline-security / baseline (pull_request) Failing after 2m44s
scan / trivy-fs (pull_request) Failing after 1m56s
2026-10-06 05:16:08 +00:00
Compare

🔧 Security-gate fix map

The gate failed on these dependency findings — fastest path to green for each:

finding package installed → fixed do this
CVE-2026-63671 (HIGH) @nuxtjs/mdc 0.21.1 → 0.22.1 merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f
CVE-2026-102829 (CRITICAL) @simple-git/argv-parser 1.1.1 → 2.0.1 no fix PR yet — npm update argv-parser --package-lock-only
GHSA-g2v6-rqmx-r4w6 (HIGH) @vue/server-renderer 3.5.40 → 3.5.42, 3.6.0-rc.6 no fix PR yet — npm update server-renderer --package-lock-only
CVE-2026-93687 (HIGH) braces 3.0.3 → ? no fix PR yet — npm update braces --package-lock-only
CVE-2026-92708 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-mcm9-63f2-9j32 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-r9w8-h9r3-54w4 (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
GHSA-x5rw-q4pp-hg5g (HIGH) devalue 5.8.2 → 5.9.3 no fix PR yet — npm update devalue --package-lock-only
CVE-2026-84375 (HIGH) js-yaml 4.3.1 → 4.3.2, 3.15.2 no fix PR yet — npm update js-yaml --package-lock-only
CVE-2026-85393 (HIGH) node-forge 1.4.0 → ? no fix PR yet — npm update node-forge --package-lock-only
CVE-2026-104846 (CRITICAL) seroval 1.5.6 → 1.6.2 no fix PR yet — npm update seroval --package-lock-only
CVE-2026-104845 (HIGH) seroval 1.5.6 → 1.6.3 no fix PR yet — npm update seroval --package-lock-only
GHSA-rgj7-g3m4-5g8c (HIGH) sharp 0.35.3 → 0.35.4 no fix PR yet — npm update sharp --package-lock-only
CVE-2026-102828 (CRITICAL) simple-git 3.36.0 → 4.0.1 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-102826 (HIGH) simple-git 3.36.0 → 4.0.0 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-102827 (HIGH) simple-git 3.36.0 → 4.0.0 no fix PR yet — npm update simple-git --package-lock-only
CVE-2026-93749 (HIGH) source-map-js 1.2.1 → 1.2.2 no fix PR yet — npm update source-map-js --package-lock-only
CVE-2026-84370 (HIGH) svgo 4.0.2 → 2.8.4, 3.3.5, 4.1.0 no fix PR yet — npm update svgo --package-lock-only
CVE-2026-19534 (HIGH) undici 8.10.0 → 6.28.1, 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-84961 (HIGH) undici 8.10.0 → 7.29.1, 8.10.2 no fix PR yet — npm update undici --package-lock-only
CVE-2026-85152 (HIGH) undici 8.10.0 → 8.10.2 no fix PR yet — npm update undici --package-lock-only

⚠ main is itself red right now — this PR likely inherits the backlog rather than adding it. Fixing main (rows above) unblocks every open PR at once.

Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.

### 🔧 Security-gate fix map <!-- tti-fixmap:5f048412d25b9c02567e50da8a71ee5a8910244a --> The gate failed on these dependency findings — fastest path to green for each: | finding | package | installed → fixed | do this | |---|---|---|---| | CVE-2026-63671 (HIGH) | `@nuxtjs/mdc` | 0.21.1 → 0.22.1 | merge #59 — fix(security): @nuxtjs/mdc ^0.22.2 (CVE-2026-63671) — hold f | | CVE-2026-102829 (CRITICAL) | `@simple-git/argv-parser` | 1.1.1 → 2.0.1 | no fix PR yet — `npm update argv-parser --package-lock-only` | | GHSA-g2v6-rqmx-r4w6 (HIGH) | `@vue/server-renderer` | 3.5.40 → 3.5.42, 3.6.0-rc.6 | no fix PR yet — `npm update server-renderer --package-lock-only` | | CVE-2026-93687 (HIGH) | `braces` | 3.0.3 → ? | no fix PR yet — `npm update braces --package-lock-only` | | CVE-2026-92708 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-mcm9-63f2-9j32 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-r9w8-h9r3-54w4 (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | GHSA-x5rw-q4pp-hg5g (HIGH) | `devalue` | 5.8.2 → 5.9.3 | no fix PR yet — `npm update devalue --package-lock-only` | | CVE-2026-84375 (HIGH) | `js-yaml` | 4.3.1 → 4.3.2, 3.15.2 | no fix PR yet — `npm update js-yaml --package-lock-only` | | CVE-2026-85393 (HIGH) | `node-forge` | 1.4.0 → ? | no fix PR yet — `npm update node-forge --package-lock-only` | | CVE-2026-104846 (CRITICAL) | `seroval` | 1.5.6 → 1.6.2 | no fix PR yet — `npm update seroval --package-lock-only` | | CVE-2026-104845 (HIGH) | `seroval` | 1.5.6 → 1.6.3 | no fix PR yet — `npm update seroval --package-lock-only` | | GHSA-rgj7-g3m4-5g8c (HIGH) | `sharp` | 0.35.3 → 0.35.4 | no fix PR yet — `npm update sharp --package-lock-only` | | CVE-2026-102828 (CRITICAL) | `simple-git` | 3.36.0 → 4.0.1 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-102826 (HIGH) | `simple-git` | 3.36.0 → 4.0.0 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-102827 (HIGH) | `simple-git` | 3.36.0 → 4.0.0 | no fix PR yet — `npm update simple-git --package-lock-only` | | CVE-2026-93749 (HIGH) | `source-map-js` | 1.2.1 → 1.2.2 | no fix PR yet — `npm update source-map-js --package-lock-only` | | CVE-2026-84370 (HIGH) | `svgo` | 4.0.2 → 2.8.4, 3.3.5, 4.1.0 | no fix PR yet — `npm update svgo --package-lock-only` | | CVE-2026-19534 (HIGH) | `undici` | 8.10.0 → 6.28.1, 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-84961 (HIGH) | `undici` | 8.10.0 → 7.29.1, 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | | CVE-2026-85152 (HIGH) | `undici` | 8.10.0 → 8.10.2 | no fix PR yet — `npm update undici --package-lock-only` | > ⚠ `main` is itself red right now — this PR likely **inherits** the backlog rather than adding it. Fixing `main` (rows above) unblocks every open PR at once. <sub>Posted once per head commit by the baseline gate (M2). A Renovate PR that only touches a manifest with no lockfile change is a broken pre-2026-08-06 artifact — check its diff before merging.</sub>
ai-review-bot left a comment

AI review · advisory

Verdict: looks good — all four reviewers found nothing that needs fixing.

⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks

Panel debate — how this review was reached

Grounding — context: 2 files under review · 90 codebase · 6 standards chunks

Round 1 — independent reviews

  • Muse Glimmer 30B (0 findings, confidence 0.95 · thought 655 + wrote 57 of 32.8k tokens · 14 s): The dependency bump to brace-expansion 5.0.12 is a straightforward security patch with matching lockfile and overrides updates and no code-level issues.
  • Gemma 4 31B (0 findings, confidence 1.0 · thought 805 + wrote 86 of 16.0k tokens · 36 s): The changes correctly update the brace-expansion dependency to version 5.0.12 in both package.json (via overrides) and package-lock.json to address a security vulnerability.
  • Mistral Medium 3.5 128B (0 findings, confidence 1.0 · wrote 84 of 16.0k tokens · 26 s): The diff correctly updates brace-expansion from v5.0.9 to v5.0.12 in both package.json overrides and package-lock.json, aligning with the security-related dependency update stated in the PR title. No
  • Laguna S 2.1 (0 findings, confidence 0.96 · wrote 768 of 65.5k tokens · 59 s): The diff is clean: it correctly bumps the brace-expansion override in package.json from 5.0.9 to 5.0.12 and updates the corresponding lockfile entry (version, resolved URL, integrity hash) to match. T

Synthesis — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity.

Transcript rv-20261006052025-2bc1d5 — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.

Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript rv-20261006052025-2bc1d5.

### AI review · advisory <!-- tti-rv:rv-20261006052025-2bc1d5: --> **Verdict: looks good** — all four reviewers found nothing that needs fixing. <sub>⚑ panel: Muse Glimmer 30B · Gemma 4 31B · Mistral Medium 3.5 128B · Laguna S 2.1 — 0 distinct, 0 confirmed, 0 below threshold, 0 refuted · web: not used · context: 2 files under review · 90 codebase · 6 standards chunks</sub> <details> <summary>Panel debate — how this review was reached</summary> **Grounding** — context: 2 files under review · 90 codebase · 6 standards chunks **Round 1 — independent reviews** - **Muse Glimmer 30B** (0 findings, confidence 0.95 · thought 655 + wrote 57 of 32.8k tokens · 14 s): The dependency bump to brace-expansion 5.0.12 is a straightforward security patch with matching lockfile and overrides updates and no code-level issues. - **Gemma 4 31B** (0 findings, confidence 1.0 · thought 805 + wrote 86 of 16.0k tokens · 36 s): The changes correctly update the `brace-expansion` dependency to version 5.0.12 in both `package.json` (via overrides) and `package-lock.json` to address a security vulnerability. - **Mistral Medium 3.5 128B** (0 findings, confidence 1.0 · wrote 84 of 16.0k tokens · 26 s): The diff correctly updates brace-expansion from v5.0.9 to v5.0.12 in both package.json overrides and package-lock.json, aligning with the security-related dependency update stated in the PR title. No - **Laguna S 2.1** (0 findings, confidence 0.96 · wrote 768 of 65.5k tokens · 59 s): The diff is clean: it correctly bumps the brace-expansion override in package.json from 5.0.9 to 5.0.12 and updates the corresponding lockfile entry (version, resolved URL, integrity hash) to match. T **Synthesis** — Laguna S 2.1 wrote the final review from 0 confirmed findings · promotion: support ≥ 2, and no refutation at high severity. <sub>Transcript `rv-20261006052025-2bc1d5` — full round outputs, web results, and model reasoning are viewable by anyone with access to this repository via the AI gateway.</sub> </details> <sub>Advisory — never a merge gate. Findings are ordered by how well the panel's own evidence checks out, strongest first. React 👍/👎 on any inline comment to tell it whether it was worth flagging — that is the only feedback this system gets, and every threshold in it is tuned from those reactions. Transcript `rv-20261006052025-2bc1d5`.</sub>
Some checks failed
baseline-security / baseline (push) Failing after 2m21s
scan / trivy-fs (push) Failing after 2m22s
ai-review / review (pull_request) Successful in 1m54s
baseline-security / baseline (pull_request) Failing after 2m44s
Required
Details
scan / trivy-fs (pull_request) Failing after 1m56s
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/npm-brace-expansion-vulnerability:renovate/npm-brace-expansion-vulnerability
git switch renovate/npm-brace-expansion-vulnerability
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
tti/tti-ux!62
No description provided.