Conversation
Owner
Author
Run Summary — remediation pass, 2026-09-30 UTCDelivered two dedicated security fixes: #3941 (
Security evidence
Needs Human Attention
|
This was referenced Sep 30, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security remediation
Raise the existing
brace-expansionoverride floor to>=5.0.12and resolve only that package from 5.0.9 → 5.0.12. Onlypnpm-workspace.yamlandpnpm-lock.yamlchange.Confirmed high advisories:
5.0.12 also resolves the same package's medium advisory GHSA-q2hr-2g5m-vwhr. No unrelated dependency updates are included. The consumer is
minimatch, used by development tooling.Sources: GitHub Advisory Database and npm advisory audit confirmed severity/ranges; npm registry
pnpm view brace-expansion@5.0.12confirmed the version/integrity. This is a same-major patch remediation; major drift was not surveyed. The floor comment records when it can be removed.Verification
pnpm bootstrap,pnpm check-types,pnpm test: passed (88 files, 4,079 tests passed, 3 todo).pnpm exec eslint,pnpm check:solutions-examples, Markdown-link gate,git diff --check: passed.pnpm lint: blocked only by the three independently confirmed highundiciadvisories already present on main, addressed separately in fix(security): exclude vulnerable undici releases #3941. No guardrails are weakened.Both independent security PRs must land for the repository-wide lint gate to pass. They touch disjoint lockfile sections; refresh against main after the first lands to satisfy strict branch protection. Automated review helper/reference access was denied by CI tool policy; no automated review verdict is claimed.