8000 fix(deps): update brace-expansion by MikeMcC399 · Pull Request #1486 · cypress-io/github-action · GitHub
[go: up one dir, main page]

Skip to content

Conversation

MikeMcC399
Copy link
Collaborator
@MikeMcC399 MikeMcC399 commented Jun 15, 2025

Situation

Dependabot and npm audit report a low severity vulnerability CVE-2025-5889 in a transient dependency:

used in action caching, action examples and ESLint related modules.

Lockfiles with vulnerable versions are:

Change

Update affected lock files to use:

@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 added bug Something isn't working tests labels Jun 15, 2025
@MikeMcC399 MikeMcC399 self-assigned this Jun 15, 2025
update transient dependencies to:
brace-expansion@1.1.12
brace-expansion@2.0.2
@MikeMcC399 MikeMcC399 force-pushed the update/brace-expansion branch from c8dda82 to 11210f9 Compare June 15, 2025 08:42
@MikeMcC399 MikeMcC399 changed the title chore(deps): update brace-expansion fix(deps): update brace-expansion Jun 15, 2025
@MikeMcC399 MikeMcC399 marked this pull request as ready for review June 15, 2025 08:46
@jennifer-shehane jennifer-shehane merged commit 6c143ab into cypress-io:master Jun 16, 2025
77 checks passed
Copy link

🎉 This PR is included in version 6.10.1 🎉

The release is available on:

Your semantic-release bot 📦🚀

@MikeMcC399 MikeMcC399 deleted the update/brace-expansion branch June 16, 2025 13:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working released tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

0