Commit dc0b779
fix: upgrade brace-expansion to 5.0.5 to address CVE-2026-33750
Add brace-expansion override to resolve Dependabot alert #20.
brace-expansion >= 4.0.0, < 5.0.5 is vulnerable to a zero-step
sequence causing process hang and memory exhaustion (CWE-400).
Rebuild dist to include the patched dependency.
Co-Authored-By: David Konigsberg <davidakonigsberg@gmail.com>1 parent da3d629 commit dc0b779
3 files changed
Lines changed: 9 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40261 | 40261 | | |
40262 | 40262 | | |
40263 | 40263 | | |
40264 | | - | |
| 40264 | + | |
40265 | 40265 | | |
40266 | 40266 | | |
40267 | 40267 | | |
| |||
40388 | 40388 | | |
40389 | 40389 | | |
40390 | 40390 | | |
40391 | | - | |
| 40391 | + | |
| 40392 | + | |
| 40393 | + | |
40392 | 40394 | | |
40393 | 40395 | | |
40394 | 40396 | | |
| |||
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
| 39 | + | |
39 | 40 | | |
40 | 41 | | |
0 commit comments