fix(deps): CVE-2026-102276 (high) + CVE-2026-102278 (high) — bump brace-expansion override to ^5.0.11 - #1928
Conversation
…VE-2026-102278) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
There was a problem hiding this comment.
TASTE.md review: complies — 0 violations. The PR only changes the brace-expansion override in pnpm-workspace.yaml and pnpm-lock.yaml; it touches no public SDK surface in packages/js-sdk or packages/python-sdk, so none of the TASTE.md rules (T-1–T-74) apply.
Package ArtifactsBuilt from 8d4d518. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-2.52.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgzCLI ( npm install ./e2b-cli-2.21.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1790924781-brace-expansion-cve-2026-102276-102278.0.tgzPython SDK ( pip install ./e2b-2.52.0+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.1+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.0+devin.1790924781.brace.expansion.cve.2026.102276.102278-py3-none-any.whl |
There was a problem hiding this comment.
LGTM, straightforward dependency pin bump.
What was reviewed: confirmed the only changes are the brace-expansion override range/target bump (<5.0.9: ^5.0.9 to <5.0.11: ^5.0.11) in pnpm-workspace.yaml and the matching pnpm-lock.yaml update (resolution hash and minimatch@ 10.2.5's dependency reference both moved from 5.0.9 to 5.0.12, consistent with the override). No application code, scripts, or other dependencies changed.
Extended reasoning...
The diff touches only pnpm-workspace.yaml and pnpm-lock.yaml, raising a transitive brace-expansion override from 5.0.9 to 5.0.11+ (lockfile resolves to 5.0.12) to address known CVEs; no security-sensitive application code is touched directly, only a dependency pin. The change is small, mechanical, and internally consistent (override and lockfile match), with no outstanding objections in the timeline, so a human does not need to review this.
…ions (CVE-2026-102276/77/78) (#1929) ## Summary The Dependabot security-update job on `main` ([run](https://github.com/e2b-dev/E2B/actions/runs/36995679736/job/110801731144)) fails because the lockfile still pins vulnerable `brace-expansion@1.1.18` (and `2.1.4`). #1928 only bumped the 5.x line; the same advisories also cover the 1.x/2.x/3.x lines, and the pnpm override floors (`^1.1.18`, `^2.1.4`) keep Dependabot from resolving a fix: ``` INFO The latest possible version of brace-expansion that can be installed is 1.1.18 INFO The earliest fixed version is 1.1.21. | security_update_not_possible | "dependency-name": "brace-expansion", "latest-resolvable-version": "1.1.18", "lowest-non-vulnerable-version": "1.1.21" | ``` Raise every `brace-expansion` override floor to the first version patched against all three advisories (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr): ```diff - brace-expansion@<1.1.18: ^1.1.18 - brace-expansion@>=2.0.0 <2.1.4: ^2.1.4 - brace-expansion@>=3.0.0 <3.0.6: ^3.0.6 - brace-expansion@>=4.0.0 <5.0.11: ^5.0.11 + brace-expansion@<1.1.21: ^1.1.21 + brace-expansion@>=2.0.0 <2.1.7: ^2.1.7 + brace-expansion@>=3.0.0 <3.0.9: ^3.0.9 + brace-expansion@>=4.0.0 <5.0.12: ^5.0.12 ``` Lockfile: `1.1.18 → 1.1.21`, `2.1.4 → 2.1.7`, `5.0.12` unchanged. All versions were published 2026-09-14, so they clear `minimumReleaseAge`. After the change, `pnpm audit` reports no `brace-expansion` advisories; `pnpm install --frozen-lockfile` and `pnpm run lint` pass. There's no changeset because only the workspace lockfile/overrides change, not the published package dependencies (same as #1928). Link to Devin session: https://app.devin.ai/sessions/148d963bf68a484bb74d1c4eb9d8e332 Open in Devin Desktop: https://app.devin.ai/desktop/session/148d963bf68a484bb74d1c4eb9d8e332?variant=devin <!-- devin-review-badge-begin --> --- <a href="https://app.devin.ai/review/e2b-dev/e2b/pull/1929" target="_blank"><picture><source media="(prefers-color-scheme: dark)" srcset="https://static.devin.ai/assets/gh-devin-review-dark.svg?v=4"><img src="https://static.devin.ai/assets/gh-devin-review-light.svg?v=4" alt="Devin Review"></picture></a> <!-- devin-review-badge-end --> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Summary
pnpm auditflagsbrace-expansion@5.0.9. The SDK pulls it in at runtime throughe2b → glob → minimatch@10.2.5 → brace-expansion.globis a runtime dependency ofpackages/js-sdk:template/utils.tsdynamically imports it to expand user-suppliedTemplate.copy()source patterns, so published code can reach it.parseCommaParts{a},b}rewriteOne PR for both high CVEs: the smallest override that clears CVE-2026-102276 (
^5.0.10) already resolves to 5.0.12. That version clears all three advisories, so two separate PRs would have identical lockfiles and conflict on the same override line. The floor is^5.0.11, the lowest version that clears both highs. 5.0.10–5.0.12 were published 2026-09-14, outside the 3-dayminimumReleaseAgewindow.No changeset: this follows earlier override-only bumps (#1869, #1851). The workspace override and lockfile aren't published.
e2bkeeps depending onglob ^13.0.6, and no releasedminimatchrequires a patchedbrace-expansionfloor, so fresh installs ofe2balready resolve to 5.0.12 through^5.0.x.Not covered here (dev-only):
brace-expansion@1.1.18(vianpm-run-all) and@2.1.4(viaopenapi-typescript → @redocly/openapi-core). Both come only from js-sdk devDependencies used for codegen and scripts, and published code can't reach them.Verified locally:
pnpm auditno longer reports the 5.x path.tests/template/utilsvitest suite passes (81 passed, 3 skipped). It includes the glob-basedgetAllFilesInPathtests.pnpm --dir packages/js-sdk run typecheckpasses.Link to Devin session: https://app.devin.ai/sessions/ee1f1bed5d9d479aa6092da48034989b
Open in Devin Desktop: https://app.devin.ai/desktop/session/ee1f1bed5d9d479aa6092da48034989b?variant=devin