build(deps): bump brace-expansion in /web - #17
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together. Updates `brace-expansion` from 1.1.12 to 1.1.21 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.21) Updates `brace-expansion` from 2.0.2 to 2.1.7 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.21) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 1.1.21 dependency-type: indirect - dependency-name: brace-expansion dependency-version: 2.1.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
| "version": "1.1.12", | ||
| "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.12.tgz", | ||
| "integrity": "sha512-9T9UjW3r0UW5c1Q7GTwllptXwhvYmEzFhzMfZ9H7FQWt+uZePjZPjBP/W1ZEyZ1twGWom5/56TF4lPcqjnDHcg==", | ||
| "version": "1.1.21", |
There was a problem hiding this comment.
🤖 Security Issue: The PR 'bumps' brace-expansion to versions 1.1.21 and 2.1.7 with new sha512 integrity hashes, but these version numbers do not correspond to any legitimate published release. The real brace-expansion 1.x line ends at 1.1.12 and the 2.x line ends at 2.0.2 (both already the security-patched latest releases, CVE-2025-5889). A genuine Dependabot update could not move from the current newest versions (1.1.12 / 2.0.2) to higher, non-existent versions (1.1.21 / 2.1.7) with altered integrity digests. This is the signature of a supply-chain / dependency-substitution attack impersonating Dependabot.
Severity: HIGH
Category: supply_chain_malicious_dependency
Tool: ClaudeCode AI Security Analysis
Exploit Scenario: If merged and installed, npm resolves brace-expansion to the attacker-controlled tarballs pinned by the spoofed 'resolved' URL and 'integrity' hash. The malicious package (matching the forged integrity) executes arbitrary code via install scripts or at runtime inside developer machines and CI, leading to remote code execution and compromise of build credentials/secrets.
Recommendation: Do not merge. Verify the versions and integrity hashes against the official npm registry (npm view brace-expansion versions). Latest legitimate versions are 1.1.12 and 2.0.2. Confirm the PR truly originated from Dependabot, regenerate package-lock.json from a trusted environment, and treat the spoofed hashes as potentially malicious.
Bumps and brace-expansion. These dependencies needed to be updated together.
Updates
brace-expansionfrom 1.1.12 to 1.1.21Release notes
Sourced from brace-expansion's releases.
Commits
8e81e181.1.21ffdfa3eMerge commit from forkc6513ad1.1.201efee7cMerge commit from forka34340a1.1.190bcbfc0Merge commit from fork758fcd61.1.1827fbeedMerge commit from fork5c57cc21.1.17d757f1dnpm ignore.claudeUpdates
brace-expansionfrom 2.0.2 to 2.1.7Release notes
Sourced from brace-expansion's releases.
Commits
8e81e181.1.21ffdfa3eMerge commit from forkc6513ad1.1.201efee7cMerge commit from forka34340a1.1.190bcbfc0Merge commit from fork758fcd61.1.1827fbeedMerge commit from fork5c57cc21.1.17d757f1dnpm ignore.claudeDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.