fix(deps): bump brace-expansion 1.x/2.x/3.x overrides to patched versions (CVE-2026-102276/77/78) - #1929
Conversation
…tched versions Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
There was a problem hiding this comment.
TASTE.md review: checked all principles (T-1–T-58). This PR only raises brace-expansion pnpm override floors in pnpm-workspace.yaml and the corresponding lockfile pins — it touches no SDK public API surface, so no rules apply. No violations found.
Package ArtifactsBuilt from cd2e7a1. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-2.52.1-devin-1790937036-brace-expansion-overrides.0.tgzCLI ( npm install ./e2b-cli-2.21.1-devin-1790937036-brace-expansion-overrides.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.1-devin-1790937036-brace-expansion-overrides.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1790937036-brace-expansion-overrides.0.tgzPython SDK ( pip install ./e2b-2.52.0+devin.1790937036.brace.expansion.overrides-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.1+devin.1790937036.brace.expansion.overrides-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.0+devin.1790937036.brace.expansion.overrides-py3-none-any.whl |
There was a problem hiding this comment.
LGTM — straightforward dependency-pin bump with no behavioral code change.
What was reviewed: the pnpm-workspace.yaml override floors for brace-expansion (1.x/2.x/3.x lines) and the corresponding pnpm-lock.yaml regeneration. Confirmed the lockfile's resolution/integrity hashes for brace-expansion@ 1.1.21 and @ 2.1.7 are present and that minimatch@ 3.1.5/5.1.9 snapshots reference the bumped versions consistently. No other brace-expansion references remain pointing at the old pinned versions, and no application source files are touched.
Extended reasoning...
The diff (64 lines total) only touches pnpm-workspace.yaml overrides and the matching pnpm-lock.yaml metadata, raising brace-expansion override floors (1.1.18->1.1.21, 2.1.4->2.1.7, 3.0.6->3.0.9, 5.0.11->5.0.12) to patch known ReDoS advisories; no application code, auth, or data-handling paths are involved. Verified the lockfile is internally consistent: new resolution hashes are present for 1.1.21 and 2.1.7, and the minimatch snapshots that depend on brace-expansion reference the bumped versions. This is mechanical, low-risk, and matches the repo's convention of pnpm-managed dependency updates with no changeset needed for a pure lockfile/override change.
Summary
The Dependabot security-update job on
main(run) fails because the lockfile still pins vulnerablebrace-expansion@1.1.18(and2.1.4). #1928 only bumped the 5.x line; the same advisories also cover the 1.x/2.x/3.x lines, and the pnpm override floors (^1.1.18,^2.1.4) keep Dependabot from resolving a fix:Raise every
brace-expansionoverride floor to the first version patched against all three advisories (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr):Lockfile:
1.1.18 → 1.1.21,2.1.4 → 2.1.7,5.0.12unchanged. All versions were published 2026-09-14, so they clearminimumReleaseAge. After the change,pnpm auditreports nobrace-expansionadvisories;pnpm install --frozen-lockfileandpnpm run lintpass. There's no changeset because only the workspace lockfile/overrides change, not the published package dependencies (same as #1928).Link to Devin session: https://app.devin.ai/sessions/148d963bf68a484bb74d1c4eb9d8e332
Open in Devin Desktop: https://app.devin.ai/desktop/session/148d963bf68a484bb74d1c4eb9d8e332?variant=devin