Skip to content

fix: downgrade brace-expansion to v2#283

Closed
G-Rath wants to merge 1 commit intoisaacs:v9from
G-Rath:v9-downgrade-brace-expansion
Closed

fix: downgrade brace-expansion to v2#283
G-Rath wants to merge 1 commit intoisaacs:v9from
G-Rath:v9-downgrade-brace-expansion

Conversation

@G-Rath
Copy link

@G-Rath G-Rath commented Feb 25, 2026

Resolves half of #282
Resolves #286

@isaacs
Copy link
Owner

isaacs commented Feb 25, 2026

Sorry, can't do that. Reintroduces a security issue.

@isaacs isaacs closed this Feb 25, 2026
@G-Rath
Copy link
Author

G-Rath commented Feb 25, 2026

@isaacs I don't understand how that is the case? The other majors below v9 are using this version of brace-expansion so theyd be vulnerable too?

If you mean a vulnerability in brace-expansion itself, I believe they've all since been backported - none of my security tools are reporting vulns at least

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants