Skip to content

fix(deps): clear the brace-expansion, fast-uri and urllib3 advisories - #217

Merged
dlamarre-dev merged 1 commit into
mainfrom
fix/audit-urllib3-brace-expansion
Oct 2, 2026
Merged

dlamarre-dev merged 1 commit into
mainfrom
fix/audit-urllib3-brace-expansion

Conversation

@dlamarre-dev

Copy link
Copy Markdown
Owner

Why

The audit steps (npm run audit, pip-audit) now fail on main, and therefore on every pull request against it, including Dependabot #214 and #216. New advisories were published against versions already pinned:

Package From → to Advisories
brace-expansion (npm, transitive) 5.0.9 → 5.0.12 GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7, GHSA-6j4f-fj2g-mc7p (high)
fast-uri (npm, transitive) 3.1.7 → 3.1.8, override ^3.1.8 GHSA-hrr3-gc8f-f4qj (moderate)
urllib3 (Python) 2.7.0 → 2.8.0 PYSEC-2026-4175, -4176, -4177

Change

  • package-lock.json: npm audit fix changes only those two packages.
  • package.json: the fast-uri override floor goes from ^3.1.7 to ^3.1.8, as in fix(deps): bump the qs and fast-uri overrides past new advisories #146, so a reinstall cannot drop back into the vulnerable range.
  • python/requirements-{erasure,steganalysis,compliance,dev}.lock: recompiled with uv pip compile --upgrade-package urllib3. Only urllib3 changes.

Checks

  • npm run audit: clean
  • pip-audit --require-hashes on every lock, with the compliance ignores already in CI: clean
  • lint and typecheck: clean

🤖 Generated with Claude Code

The audit steps started failing on main, and so on every pull request
against it, on advisories published against versions already pinned:

  - brace-expansion 5.0.9 (GHSA-q2hr-2g5m-vwhr, GHSA-qhr7-859c-m2p7,
    GHSA-6j4f-fj2g-mc7p, high): transitive, lockfile moved to 5.0.12.
  - fast-uri 3.1.7 (GHSA-hrr3-gc8f-f4qj, moderate): lockfile moved to
    3.1.8, and the override floor raised to ^3.1.8 so a reinstall cannot
    resolve back into the vulnerable range.
  - urllib3 2.7.0 (PYSEC-2026-4175, -4176, -4177): 2.8.0 in the erasure,
    steganalysis, compliance and dev locks, recompiled with
    `uv pip compile --upgrade-package urllib3` so nothing else moves.

npm run audit and pip-audit on every lock (with the compliance ignores
the CI already carries) are clean.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@dlamarre-dev
dlamarre-dev merged commit 1e50d5d into main Oct 2, 2026
17 checks passed
@dlamarre-dev
dlamarre-dev deleted the fix/audit-urllib3-brace-expansion branch October 2, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants