Repository navigation
fix(deps): bump brace-expansion 1.x/2.x/3.x/5.x overrides to patched versions - #1932
devin-ai-integration[bot] wants to merge 1 commit into
Conversation
…HSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p) Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
There was a problem hiding this comment.
TASTE.md review: complies, no violations. This PR only bumps the brace-expansion overrides in pnpm-workspace.yaml/pnpm-lock.yaml, and none of the TASTE.md principles (parity, API shape, streaming, lifecycle, template builder, timeouts, config, module structure, errors, deprecation, docs) cover that.
Package ArtifactsBuilt from 39c445c. Download artifacts from this workflow run. JS SDK ( npm install ./e2b-2.52.1-devin-1790938795-brace-expansion-1x-2x.0.tgzCLI ( npm install ./e2b-cli-2.21.1-devin-1790938795-brace-expansion-1x-2x.0.tgzCode Interpreter JS SDK ( npm install ./e2b-code-interpreter-2.8.1-devin-1790938795-brace-expansion-1x-2x.0.tgzDesktop JS SDK ( npm install ./e2b-desktop-2.4.1-devin-1790938795-brace-expansion-1x-2x.0.tgzPython SDK ( pip install ./e2b-2.52.0+devin.1790938795.brace.expansion.1x.2x-py3-none-any.whlCode Interpreter Python SDK ( pip install ./e2b_code_interpreter-2.10.1+devin.1790938795.brace.expansion.1x.2x-py3-none-any.whlDesktop Python SDK ( pip install ./e2b_desktop-2.6.0+devin.1790938795.brace.expansion.1x.2x-py3-none-any.whl |
There was a problem hiding this comment.
Looks good, straightforward dependency-override version bump.
What was reviewed: confirmed the pnpm-workspace.yaml override thresholds for brace-expansion were raised (1.1.18→1.1.21, 2.1.4→2.1.7, 3.0.6→3.0.9, 5.0.11→5.0.12) and that pnpm-lock.yaml was regenerated consistently — new resolution hashes for brace-expansion@ 1.1.21/2.1.7 and updated minimatch@ 3.1.5/5.1.9 dependency pins match the new versions. No other packages, code, or specs are touched; diff is 24/8 lines across exactly the two listed files.
Extended reasoning...
Pure dependency-security patch: raises pnpm override floors for brace-expansion in pnpm-workspace.yaml and regenerates pnpm-lock.yaml accordingly, touching no application code, specs, or public API surface. No security-sensitive logic is introduced (the change only tightens version constraints to pull in already-patched upstream releases); verified the lockfile hashes/snapshots are internally consistent with the new versions. Small, mechanical, and self-contained, matching the PR description exactly.
|
is this already merged? |
Summary
The
Dependabotsecurity-update job onmain(job 110810174316) fails because the workspace override pinsbrace-expansion1.x below the fixed version, so Dependabot can't bump it:#1928 raised only the 5.x override. The same advisories (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr) also cover the 1.x/2.x/3.x lines, and the open Dependabot alerts (#387–#394) still flag them. This PR raises every override floor to the version that clears all three advisories:
All target versions were published 2026-09-14, so they fall outside the 3-day
minimumReleaseAge. 1.x/2.x reach the repo only through dev dependencies (npm-run-all,openapi-typescript), and lockfile/workspace overrides aren't published, so there is no changeset (same as #1928).Verified locally:
pnpm install --frozen-lockfilesucceeds,pnpm auditreports nothing forbrace-expansion,tests/template/utilspasses (81 passed, 3 skipped), andpnpm --dir packages/js-sdk run typecheckpasses.Link to Devin session: https://app.devin.ai/sessions/967351cbda7f4b25b64e4adc3b229bbc
Open in Devin Desktop: https://app.devin.ai/desktop/session/967351cbda7f4b25b64e4adc3b229bbc?variant=devin