🔒 Refresh brace-expansion security resolutions - #338
Merged
Conversation
Keep each minimatch major on its compatible patched brace-expansion release without introducing a global override.
Robdel12
marked this pull request as ready for review
August 9, 2026 22:40
Robdel12
enabled auto-merge (squash)
August 9, 2026 22:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The workspace lockfile pinned
brace-expansionto versions affected by a recent denial-of-service advisory. The runtime dependency path isglob→minimatch→brace-expansion;globis used for plugin and screenshot discovery, so the vulnerable package is part of the CLI dependency tree even though Vizzly does not import it directly.Approach
Refresh the lockfile to patched releases within each existing
brace-expansionmajor: 1.1.18, 2.1.4, and 5.0.9. The existing dependency ranges already allow these versions, so this avoids a global pnpm override that would mix incompatible module APIs.Evidence
The lockfile parses cleanly, frozen-lockfile installation succeeds, the production build completes, and the full Node test suite passes with 2,018 tests passing and no failures.
The advisory affects
brace-expansion5.x versions before 5.0.8: GHSA-mh99-v99m-4gvg