Skip to content

UID2-8003: preventive upgrade brace-expansion to 5.0.10 (CVE-2026-102276) - #227

Merged
swibi-ttd merged 1 commit into
mainfrom
swi-cve-2026-102276
Oct 2, 2026
Merged

swibi-ttd merged 1 commit into
mainfrom
swi-cve-2026-102276

Conversation

@swibi-ttd

Copy link
Copy Markdown
Contributor

Preventive update for CVE-2026-102276 (HIGH, brace-expansion): 5.0.9 → 5.0.10.

Not affected in the assessed configuration; this update passed Trivy verification.

Why this remedy: brace-expansion@5 was already pinned to 5.0.9 via an existing overrides entry in each of the 7 web-integrations subproject package.json files; I bumped each to the lowest fixed version 5.0.10 (matching existing override style/ordering) and regenerated each package-lock.json with npm install --package-lock-only. All 7 lockfiles now resolve brace-expansion to 5.0.10 and Trivy no longer reports CVE-2026-102276 (verified: 0 occurrences). The manifests are not at the repo root; the root package.json has no brace-expansion override and no lockfile brace-expansion node, so it was left unchanged. npm 11.19.0 was used (not the stalled 10.5.0), so no npm@10.9.9 workaround was needed.

Lockfiles regenerated with: npm install --package-lock-only (run in each of the 7 web-integrations subprojects)

Verified with trivy fs: CVE-2026-102276 was reported before the change and is gone after it (20 finding(s) before, 19 after).

Fix notes

brace-expansion 5.0.9 → 5.0.10 (CVE-2026-102276)

What changed

Each of the 7 web-integrations subprojects already pins brace-expansion@5 to 5.0.9 through an existing overrides block. I bumped that single override entry to 5.0.10 (the lowest fixed version on the 5.x line) in every one, preserving the existing key ordering and style, then regenerated the corresponding package-lock.json with npm install --package-lock-only (no node_modules, no direct-dependency changes).

Updated projects:

  • web-integrations/server-side
  • web-integrations/prebid-integrations/client-server
  • web-integrations/google-secure-signals/client-server
  • web-integrations/google-secure-signals/server-side
  • web-integrations/google-secure-signals/react-client-side
  • web-integrations/javascript-sdk/client-server
  • web-integrations/javascript-sdk/react-client-side

Why this version

5.0.10 is the first fixed release on the installed 5.x line (advisory fixed versions: 5.0.10, 3.0.7, 2.1.5, 1.1.19). Staying on 5.x via the existing override is the smallest, non-breaking change and matches the team convention of pinning through overrides rather than bumping a transitive parent (brace-expansion arrives transitively via minimatch and ejs→jake→filelist).

What was regenerated

All 7 package-lock.json files; each now resolves node_modules/brace-expansion to 5.0.10.

Verification

trivy fs --scanners vuln --skip-dirs node_modules . → CVE-2026-102276 no longer reported (0 occurrences).

Reviewer notes

  • The repo root package.json/package-lock.json have no brace-expansion node and no related override, so they were intentionally left untouched.
  • Trivy still reports the newer, separate advisories CVE-2026-102277 (MEDIUM) and CVE-2026-102278 (HIGH) on brace-expansion, which require 5.0.11/5.0.12. Those are distinct findings outside the scope of this job (CVE-2026-102276) and were not addressed here.
  • This was a preventive upgrade on an already-existing version pin; no application code, Dockerfile, or CI changes were made.

The impact assessment is recorded on the ticket named in the PR title.


Opened by uid2-vul-scan-agent (general_use_claude-opus-4-8). Please review the version choice and changes.

…0.9 -> 5.0.10

brace-expansion@5 was already pinned to 5.0.9 via an existing `overrides` entry in each of the 7 web-integrations subproject package.json files; I bumped each to the lowest fixed version 5.0.10 (matching existing override style/ordering) and regenerated each package-lock.json with `npm install --package-lock-only`. All 7 lockfiles now resolve brace-expansion to 5.0.10 and Trivy no longer reports CVE-2026-102276 (verified: 0 occurrences). The manifests are not at the repo root; the root package.json has no brace-expansion override and no lockfile brace-expansion node, so it was left unchanged. npm 11.19.0 was used (not the stalled 10.5.0), so no npm@10.9.9 workaround was needed.

Not affected in the assessed configuration; preventive update.
@swibi-ttd
swibi-ttd merged commit d740a8c into main Oct 2, 2026
1 of 3 checks passed
@swibi-ttd
swibi-ttd deleted the swi-cve-2026-102276 branch October 2, 2026 03:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants