Update brace-expansion transitive dependencies - #1105
Raymond Zhao (rzhao271) with Copilot wants to merge 3 commits into
Conversation
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
|
Copilot Please first revert all dependency and lockfile changes made in this PR so the branch is restored to its original dependency state. Then regenerate the update from that clean baseline while observing the repository’s 7-day npm release hold: npm update brace-expansion --package-lock-only --min-release-age=7
npm install --min-release-age=7
npm testThe Component Governance floor for the reported dependency path is |
Co-authored-by: rzhao271 <7199958+rzhao271@users.noreply.github.com>
Addressed in |
Component Governance flagged a vulnerable
brace-expansionversion in the npm dependency graph. This updates the lockfile-resolved transitive dependency versions without adding overrides or force-based resolution.Dependency updates
brace-expansionlockfile entries to patched versions within existing semver ranges:2.xpaths →2.1.71.xand5.xpaths → patched current releasesScope
package-lock.jsononly