Skip to content

chore: upgrade brace-expansion to address CVE-2026-13149#1471

Merged
jsourcebot merged 2 commits into
mainfrom
linear/sou-1549-sourcebot-devsourcebot-cve-2026-13149-brace-expansion-ce32
Jul 23, 2026
Merged

chore: upgrade brace-expansion to address CVE-2026-13149#1471
jsourcebot merged 2 commits into
mainfrom
linear/sou-1549-sourcebot-devsourcebot-cve-2026-13149-brace-expansion-ce32

Conversation

@linear-code

@linear-code linear-code Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-1549

Refreshes brace-expansion in yarn.lock to patched versions to address CVE-2026-13149 (DoS via exponential-time complexity in expand()).

The existing ^1.1.13, ^2.0.3, and ^5.0.5 ranges (all requested transitively via minimatch) already admitted the patched releases, so only a lockfile refresh (yarn up -R brace-expansion) was needed:

  • 1.1.141.1.16
  • 2.1.02.1.2
  • 5.0.65.0.7

yarn why brace-expansion confirms all three instances are now on patched versions.


Note

Low Risk
Dependency patch with no source changes; low risk aside from routine transitive upgrade verification.

Overview
Refreshes transitive brace-expansion in yarn.lock to patched releases (1.1.16, 2.1.2, 5.0.7) to mitigate CVE-2026-13149 (DoS from exponential-time behavior in expand()). Existing yarn resolution ranges already allowed these versions, so this is a lockfile-only bump—no package.json or application code changes.

Documents the fix under Unreleased → Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit 4670693. Bugbot is set up for automated code reviews on this repo. Configure here.

@linear-code
linear-code Bot force-pushed the linear/sou-1549-sourcebot-devsourcebot-cve-2026-13149-brace-expansion-ce32 branch from 8709c45 to a3b53ab Compare July 21, 2026 13:39
@github-actions

github-actions Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2222
Resolved (non-standard) 8
Unresolved 0
Strong copyleft 0
Weak copyleft 39

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.0.5 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.2.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.0.4 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.2.4 LGPL-3.0-or-later
@img/sharp-wasm32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-wasm32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.33.5 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.34.5 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.11 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (8)
Package Version Original Resolved Source
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 GitHub repo (LICENSE file: Apache License 2.0)
khroma 2.1.0 UNKNOWN MIT GitHub repo (MIT license in sidebar and LICENSE file)
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 GitHub repo (LICENSE file: Apache License 2.0)
map-stream 0.1.0 UNKNOWN MIT GitHub repo (MIT license in sidebar and LICENCE file)
memorystream 0.3.1 UNKNOWN MIT npm registry metadata (licenses: [{type:MIT}])
pause-stream 0.0.11 ["MIT","Apache2"] (object) MIT OR Apache-2.0 extracted from object (license array [MIT, Apache2])
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 GitHub repo (LICENSE file: Apache License 2.0)
valid-url 1.0.9 UNKNOWN MIT GitHub repo (LICENSE file: MIT license)

@brendan-kellam
brendan-kellam marked this pull request as ready for review July 21, 2026 14:08
…ebot-devsourcebot-cve-2026-13149-brace-expansion-ce32

# Conflicts:
#	CHANGELOG.md
@jsourcebot
jsourcebot merged commit 8618ed2 into main Jul 23, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant