fix(deps): bump brace-expansion to 5.0.8 (supersedes #45) - #53
Conversation
|
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_20a4ede7-0bd3-41a7-9c78-b6122bc31efa) |
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Team Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
✨ Simplify code
Comment |
|
No reviewable files after applying ignore patterns. |
🤖 CodeAnt AI — Review Status
|
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_5ae521d6-140a-478c-96b4-803b074f12cc) |
ApprovabilityVerdict: Not approved Macroscope's review found this PR not approvable — The change is confined to an ignored lockfile path and appears limited to a dev-only transitive dependency, so it should not alter published SDK behavior. Its stated purpose is to remediate a HIGH security advisory, making human review required under the review policy. Not approved because:
Review your spending limits in Billing settings. You can add or adjust custom eligibility rules. Learn more. |
User description
User description
Clears the
brace-expansionHIGH (alert #3). Lockfile only — 4 lines.Supersedes #45, which bumps to
5.0.7and clears nothing. Same fix as wave-av/mcp-server#67; the fleet-wide reasoning is in wave-av/claude-workstation#562.Why #45 is a no-op — measured on this repo
There are two live
brace-expansionadvisories. The one on our alert is the older>= 3.0.0, < 5.0.7(fix5.0.7). The newer is GHSA-mh99-v99m-4gvg, range<= 5.0.7, patched only in5.0.8— so5.0.7lands inside it.I pinned each version in the lockfile and ran the audit rather than reasoning about it:
brace-expansion5.0.6(main)5.0.7(what #45 ships)range: <=5.0.75.0.8(this PR)Why 5.0.8 is safe here specifically
This is the part that doesn't generalise.
minimatch@3.1.5doesconst expand = require('brace-expansion')and calls the result as a function; every patched release exports an object. On aminimatch@3tree the "fix" throwsTypeError: expand is not a functionat runtime whilenpm auditreports clean — that's claude-workstation#554, where it also passed 195/195 tests.This repo has exactly one tree and it's
minimatch@10.2.5, confirmed by reading the ref rather than a working copy:minimatch@10uses named exports, so the object shape is what it already expects. Verified by driving the consumer, sincenpm auditnever loads the module:That last line is the exact shape that breaks
minimatch@3— and brace expansion still resolves correctly throughminimatch@10.One thing in the diff worth naming
5.0.8narrows its ownenginesfrom"18 || 20 || >=22"to"20 || >=22"— it drops Node 18. That does not propagate to consumers of@wave-av/sdk:brace-expansionis"dev": truehere, reached only througheslint, so it never enters the published dependency graph and our ownengines: >=18.0.0is unaffected. CI runs Node 20 (lint.yml) and 22 (release.yml,publish.yml), both satisfied.Verification
CI can't run — Actions are refusing every job org-wide on an account-level billing lock (
plan=free,locked=yes, re-confirmed live today). All local, on Node 22.14.0:Measurement caveat: this workstation exports
NODE_ENV=production, which makesnpm auditinheritomit=devand silently hide dev-scope entries — including this one. Every figure above was taken withNODE_ENV=developmentset explicitly. Anyone re-checking needs to do the same or they'll see a different, wrong number.Separate finding, not fixed here
While measuring the baseline I found a HIGH that Dependabot is not reporting:
postcss@8.5.15, dev-only viatsup/vite, vulnerable to GHSA-r28c-9q8g-f849 (<= 8.5.17, fix8.5.18, published 2026-07-24). It's in the GitHub Advisory Database, but this repo's alert list has onlybrace-expansionandesbuild. Filed separately rather than folded into this diff.Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is enabled.Note
Low Risk
Dev-only lockfile update with no runtime or published dependency impact; security fix validated against the repo’s minimatch@10 consumer.
Overview
Lockfile-only bump of dev dependency
brace-expansionfrom 5.0.6 to 5.0.8 to clear a HIGH security advisory that 5.0.7 would not fully address. The change is on theeslint→@eslint/config-array→minimatchpath and does not alter the published SDK dependency graph.The upgraded package also narrows its own
enginesto20 || >=22(dropping Node 18); that constraint applies only to this dev transitive and does not change the repo’s>=18.0.0engine declaration.Reviewed by Cursor Bugbot for commit cffe2b3. Bugbot is set up for automated code reviews on this repo. Configure here.
Summary by cubic
Bumps
brace-expansionto 5.0.8 in the lockfile to clear the HIGH advisory that a 5.0.7 bump wouldn't fully resolve. Dev-only, no runtime impact; the merge frommainadds no other changes.eslint→@eslint/config-array→minimatch, so nothing published changes.enginesnarrows to"20 || >=22"; safe given this is dev-only and CI runs Node 20/22.Written for commit cffe2b3. Summary will update on new commits.
CodeAnt-AI Description
Update the development dependency to a security-fixed brace expansion release
What Changed
brace-expansionfrom 5.0.6 to 5.0.8 in the lockfileImpact
✅ High-severity dependency alert resolved✅ Safer development tooling✅ Node.js 20+ compatibility made explicit💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.
PR Type
Bug fix, Other
Description
Align SDK clip/voice contracts with live gateway, fixing API discrepancies
Bump zod to 4.3.6 for type validation improvements
Update brace-expansion to 5.0.9 for security and dependency fixes
Diagram Walkthrough
File Walkthrough