Skip to content

[HIGH] Bump brace-expansion to patched releases - #58337

Open
OskarEichler wants to merge 1 commit into
react:mainfrom
OskarEichler:codex/security-brace-expansion
Open

OskarEichler wants to merge 1 commit into
react:mainfrom
OskarEichler:codex/security-brace-expansion

Conversation

@OskarEichler

@OskarEichler OskarEichler commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • refresh this existing security PR onto current main
  • update brace-expansion to the first currently patched release on every active major line: 1.1.21, 2.1.7, and 5.0.12
  • deduplicate the ^2.0.1 and ^2.0.2 lockfile selectors
  • keep all package manifests and semver selectors unchanged

Diagnosis

The latest main SHA a7f81c841e6e1d526ce4ae311ea737ffb748b71f had a deterministic Dependabot failure in update #1603005744: security_update_not_possible because the lockfile contained vulnerable brace-expansion releases on three major lines.

GitHub's open alerts currently require:

  • < 1.1.21 → 1.1.21
  • >= 2.0.0, < 2.1.7 → 2.1.7
  • >= 4.0.0, < 5.0.12 → 5.0.12

Commit a7f81c841e6e1d526ce4ae311ea737ffb748b71f introduced a new brace-expansion@^2.0.2 lock entry at 2.0.2 through flow-api-translator@0.333.0. The vulnerable 1.x and 5.x entries predate that commit, so there is no single introducing commit for the full issue.

Two iOS SwiftPM failures on the same SHA were investigated separately and are not addressed here: one runner failed to list a GitHub artifact with ENOTFOUND; the other transiently failed to resolve Hermes 260318099.0.4 even though the same artifact and workflow passed on the parent SHA less than an hour earlier. Those are infrastructure flakes, not evidence for a lockfile regression.

Test Plan

  • yarn install --frozen-lockfile --ignore-scripts — passed
  • yarn why brace-expansion — only 1.1.21, 2.1.7, and 5.0.12
  • yarn audit --json — no brace-expansion advisories; unrelated repository-wide advisories remain
  • yarn test --runInBand — 238/238 suites passed; 6,107 tests passed, 1 skipped; 1,681 snapshots passed. Jest retained its pre-existing open handle after reporting success, so the host command was terminated after completion.
  • git diff --check — passed

Risk / limitations

Lockfile-only change within the existing dependency ranges. No runtime source or package manifest changes. CI still needs to confirm the update on GitHub-hosted runners; this PR intentionally does not mask or suppress the unrelated SwiftPM infrastructure failures.

Changelog:

[INTERNAL] [SECURITY] - Bump brace-expansion to patched releases.

@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Sep 4, 2026
@facebook-github-tools facebook-github-tools Bot added the Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team. label Sep 4, 2026
Refresh the existing security update against current main and select the first patched release for each active major line.

The 2.x selectors are also deduplicated now that both resolve to the same safe version.
@cortinico
cortinico force-pushed the codex/security-brace-expansion branch from 2b78e08 to dc863a4 Compare October 1, 2026 17:02
@cortinico cortinico changed the title [HIGH] Bump brace-expansion patch releases [HIGH] Bump brace-expansion to patched releases Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Shared with Meta Applied via automation to indicate that an Issue or Pull Request has been shared with the team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant