fix(deps): patch brace-expansion to >= 5.0.5 (CVE-2026-33750)#333
fix(deps): patch brace-expansion to >= 5.0.5 (CVE-2026-33750)#333
Conversation
Infinite loop DoS via zero step value in brace patterns. Refs: CIP-2938
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (1)
📝 WalkthroughWalkthroughA pnpm dependency override was added to Changes
Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes Suggested reviewers
Poem
🚥 Pre-merge checks | ✅ 3✅ Passed checks (3 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Changes
brace-expansion@^5(>=5.0.5)pnpm-lock.yamlTest plan
pnpm why brace-expansionshows 5.0.5, no 5.0.3Refs: CIP-2938
Summary by CodeRabbit