Skip to content

chore(deps-dev): bump brace-expansion from 1.1.16 to 1.1.21 in /npm-package - #1946

Merged
Changyong Gong (chagong) merged 1 commit into
developfrom
dependabot/npm_and_yarn/npm-package/brace-expansion-1.1.21
Oct 3, 2026
Merged

Changyong Gong (chagong) merged 1 commit into
developfrom
dependabot/npm_and_yarn/npm-package/brace-expansion-1.1.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.16 to 1.1.21.

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 2, 2026
@chagong

Copy link
Copy Markdown
Contributor

Dependabot (@dependabot) rebase

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.16 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.16...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/npm-package/brace-expansion-1.1.21 branch from 2da6e5f to 3c8f8d8 Compare October 3, 2026 08:05

@chagong Changyong Gong (chagong) left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security patch is lockfile-only, the transitive ESLint dependency remains required, and all current-head checks pass.

@chagong
Changyong Gong (chagong) merged commit 7e0fd2a into develop Oct 3, 2026
16 checks passed
@chagong
Changyong Gong (chagong) deleted the dependabot/npm_and_yarn/npm-package/brace-expansion-1.1.21 branch October 3, 2026 08:24
@chagong

Copy link
Copy Markdown
Contributor

Decision: MERGED

Dependabot PR Manager result

Repository: microsoft/vscode-gradle
Pull request: microsoft/vscode-gradle#1946 — chore(deps-dev): bump brace-expansion from 1.1.16 to 1.1.21 in /npm-package
Update: brace-expansion 1.1.16 -> 1.1.21 (patch, indirect development dependency, security-related; fixes five CPU, memory, and recursion denial-of-service advisories).
Safety assessment: Verified a signed, bot-only head and a lockfile-only Standard Dependency Gate diff. The package remains required transitively by ESLint through minimatch; the patch stays within ^1.1.7 and is low risk.
Final state: Head 3c8f8d812a62b2461ac8bf1f36d55ff66cb632f9; merged via squash as 7e0fd2a3294874f14a3f4be1cda363cb8d50c089; review APPROVED; CI 16/16 successful with no failed or non-terminal checks.
Actions taken: Requested and verified Dependabot rebase 2da6e5fc50600cedce82f90f5782d4f0df714f69 -> 3c8f8d812a62b2461ac8bf1f36d55ff66cb632f9; clean npm ci and npm explain brace-expansion succeeded; isolated compile failure was reproduced unchanged on the merge base and classified UNRELATED because generated API/protobuf inputs were absent; approved the current head and squash-merged it.
Reason: None
Next action: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant