fix(deps): bump brace-expansion to 5.0.8 (supersedes #45) - #53
Conversation
|
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_20a4ede7-0bd3-41a7-9c78-b6122bc31efa) |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
|
No reviewable files after applying ignore patterns. |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_5ae521d6-140a-478c-96b4-803b074f12cc) |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The change is confined to an ignored lockfile path and appears limited to a dev-only transitive dependency, so it should not alter published SDK behavior. Its stated purpose is to remediate a HIGH security advisory, making human review required under the review policy. Not approved because:
Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more. |
…-0-8 # Conflicts: # package-lock.json
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_50b4feb4-f427-432d-9b3f-34b2df79f8ae) |
User description
User description
Clears the
brace-expansionHIGH (alert #3). Lockfile only — 4 lines.Supersedes #45, which bumps to
5.0.7and clears nothing. Same fix as wave-av/mcp-server#67; the fleet-wide reasoning is in wave-av/claude-workstation#562.Why #45 is a no-op — measured on this repo
There are two live
brace-expansionadvisories. The one on our alert is the older>= 3.0.0, < 5.0.7(fix5.0.7). The newer is GHSA-mh99-v99m-4gvg, range<= 5.0.7, patched only in5.0.8— so5.0.7lands inside it.I pinned each version in the lockfile and ran the audit rather than reasoning about it:
brace-expansion5.0.6(main)5.0.7(what #45 ships)range: <=5.0.75.0.8(this PR)Why 5.0.8 is safe here specifically
This is the part that doesn't generalise.
minimatch@3.1.5doesconst expand = require('brace-expansion')and calls the result as a function; every patched release exports an object. On aminimatch@3tree the "fix" throwsTypeError: expand is not a functionat runtime whilenpm auditreports clean — that's claude-workstation#554, where it also passed 195/195 tests.This repo has exactly one tree and it's
minimatch@10.2.5, confirmed by reading the ref rather than a working copy:minimatch@10uses named exports, so the object shape is what it already expects. Verified by driving the consumer, sincenpm auditnever loads the module:That last line is the exact shape that breaks
minimatch@3— and brace expansion still resolves correctly throughminimatch@10.One thing in the diff worth naming
5.0.8narrows its ownenginesfrom"18 || 20 || >=22"to"20 || >=22"— it drops Node 18. That does not propagate to consumers of@wave-av/sdk:brace-expansionis"dev": truehere, reached only througheslint, so it never enters the published dependency graph and our ownengines: >=18.0.0is unaffected. CI runs Node 20 (lint.yml) and 22 (release.yml,publish.yml), both satisfied.Verification
CI can't run — Actions are refusing every job org-wide on an account-level billing lock (
plan=free,locked=yes, re-confirmed live today). All local, on Node 22.14.0:Measurement caveat: this workstation exports
NODE_ENV=production, which makesnpm auditinheritomit=devand silently hide dev-scope entries — including this one. Every figure above was taken withNODE_ENV=developmentset explicitly. Anyone re-checking needs to do the same or they'll see a different, wrong number.Separate finding, not fixed here
While measuring the baseline I found a HIGH that Dependabot is not reporting:
postcss@8.5.15, dev-only viatsup/vite, vulnerable to GHSA-r28c-9q8g-f849 (<= 8.5.17, fix8.5.18, published 2026-07-24). It's in the GitHub Advisory Database, but this repo's alert list has onlybrace-expansionandesbuild. Filed separately rather than folded into this diff.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is enabled.Note
Low Risk
Dev-only lockfile security bump with no runtime or published dependency impact; CI already runs Node 20/22.
Overview
Lockfile-only update bumps transitive dev dependency
brace-expansionfrom 5.0.6 to 5.0.8 (viaeslint→@eslint/config-array→minimatch) so the HIGH advisory GHSA-mh99-v99m-4gvg is cleared—5.0.7 would still fall inside the vulnerable<= 5.0.7range.Nothing in the published
@wave-av/sdkgraph changes;minimatch@10already uses named exports compatible with the patched package shape. 5.0.8 also tightensenginesto Node 20 || >=22 for that package only, which does not affect this package’sengines: >=18because the dependency staysdev: true.Reviewed by Cursor Bugbot for commit 0414df7. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Bumps
brace-expansionto 5.0.8 in the lockfile to clear the HIGH advisory that a 5.0.7 bump wouldn't fully resolve. Dev-only, no runtime impact; the merge frommainadds no other changes.5.0.7still sits inside the newer advisory (GHSA-mh99-v99m-4gvg, patched only in5.0.8), confirmed by pinning each version and re-runningnpm audit.minimatch@10tree (named exports); the patched export shape breaksminimatch@3consumers at runtime.enginesnarrows to"20 || >=22"; dev-only, so the repo's>=18.0.0is unaffected. CI runs Node 20/22; verified locally on Node 22 (CI was blocked by an org-wide billing lock). Re-checkingnpm auditrequiresNODE_ENV=development, since the shell default hides dev-scope entries.Written for commit 0414df7. Summary will update on new commits.
CodeAnt-AI Description
Update the development dependency to a security-fixed brace expansion release
What Changed
brace-expansionfrom 5.0.6 to 5.0.8 in the lockfileImpact
✅ High-severity dependency alert resolved✅ Safer development tooling✅ Node.js 20+ compatibility made explicit💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
PR Type
Bug fix
Description
Update
clips.create()to use recording ID + time strings instead of nested source objectModify
voice.synthesize()to return ArrayBuffer and use /v1/voice endpointAdd
responseTypesupport to WaveClient for binary responsesDiagram Walkthrough
File Walkthrough