UID2-8003: preventive upgrade brace-expansion to 5.0.10 (CVE-2026-102276) - #227
Merged
Merged
Conversation
…0.9 -> 5.0.10 brace-expansion@5 was already pinned to 5.0.9 via an existing `overrides` entry in each of the 7 web-integrations subproject package.json files; I bumped each to the lowest fixed version 5.0.10 (matching existing override style/ordering) and regenerated each package-lock.json with `npm install --package-lock-only`. All 7 lockfiles now resolve brace-expansion to 5.0.10 and Trivy no longer reports CVE-2026-102276 (verified: 0 occurrences). The manifests are not at the repo root; the root package.json has no brace-expansion override and no lockfile brace-expansion node, so it was left unchanged. npm 11.19.0 was used (not the stalled 10.5.0), so no npm@10.9.9 workaround was needed. Not affected in the assessed configuration; preventive update.
BehnamMozafari
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Preventive update for CVE-2026-102276 (HIGH,
brace-expansion):5.0.9→5.0.10.Not affected in the assessed configuration; this update passed Trivy verification.
Why this remedy: brace-expansion@5 was already pinned to 5.0.9 via an existing
overridesentry in each of the 7 web-integrations subproject package.json files; I bumped each to the lowest fixed version 5.0.10 (matching existing override style/ordering) and regenerated each package-lock.json withnpm install --package-lock-only. All 7 lockfiles now resolve brace-expansion to 5.0.10 and Trivy no longer reports CVE-2026-102276 (verified: 0 occurrences). The manifests are not at the repo root; the root package.json has no brace-expansion override and no lockfile brace-expansion node, so it was left unchanged. npm 11.19.0 was used (not the stalled 10.5.0), so no npm@10.9.9 workaround was needed.Lockfiles regenerated with:
npm install --package-lock-only (run in each of the 7 web-integrations subprojects)Verified with
trivy fs: CVE-2026-102276 was reported before the change and is gone after it (20 finding(s) before, 19 after).Fix notes
brace-expansion 5.0.9 → 5.0.10 (CVE-2026-102276)
What changed
Each of the 7
web-integrationssubprojects already pinsbrace-expansion@5to5.0.9through an existingoverridesblock. I bumped that single override entry to 5.0.10 (the lowest fixed version on the 5.x line) in every one, preserving the existing key ordering and style, then regenerated the correspondingpackage-lock.jsonwithnpm install --package-lock-only(nonode_modules, no direct-dependency changes).Updated projects:
web-integrations/server-sideweb-integrations/prebid-integrations/client-serverweb-integrations/google-secure-signals/client-serverweb-integrations/google-secure-signals/server-sideweb-integrations/google-secure-signals/react-client-sideweb-integrations/javascript-sdk/client-serverweb-integrations/javascript-sdk/react-client-sideWhy this version
5.0.10 is the first fixed release on the installed 5.x line (advisory fixed versions: 5.0.10, 3.0.7, 2.1.5, 1.1.19). Staying on 5.x via the existing override is the smallest, non-breaking change and matches the team convention of pinning through
overridesrather than bumping a transitive parent (brace-expansion arrives transitively via minimatch and ejs→jake→filelist).What was regenerated
All 7
package-lock.jsonfiles; each now resolvesnode_modules/brace-expansionto5.0.10.Verification
trivy fs --scanners vuln --skip-dirs node_modules .→ CVE-2026-102276 no longer reported (0 occurrences).Reviewer notes
package.json/package-lock.jsonhave no brace-expansion node and no related override, so they were intentionally left untouched.The impact assessment is recorded on the ticket named in the PR title.
Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8). Please review the version choice and changes.