Skip to content

fix(deps): bump brace-expansion from 1.1.18 to 1.1.21 - #1942

Merged
Changyong Gong (chagong) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/brace-expansion-1.1.21
Oct 10, 2026
Merged

Changyong Gong (chagong) merged 1 commit into
mainfrom
dependabot/npm_and_yarn/brace-expansion-1.1.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.18 to 1.1.21.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.18 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.18...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 10, 2026
@chagong
Changyong Gong (chagong) merged commit 4aafc3b into main Oct 10, 2026
9 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/brace-expansion-1.1.21 branch October 10, 2026 08:53
@chagong

Copy link
Copy Markdown
Contributor

Decision: MERGED

Dependabot PR Manager result

Repository: microsoft/vscode-java-test
Pull request: microsoft/vscode-java-test#1942 - fix(deps): bump brace-expansion from 1.1.18 to 1.1.21
Update: brace-expansion 1.1.18 -> 1.1.21, 2.1.4 -> 2.1.7, and 5.0.9 -> 5.0.12; three transitive patch updates with security hardening.
Safety assessment: Dependabot-only history; Standard Dependency Gate passed. Lockfile-only changes retain needed coverage-pattern matching, test discovery, Mocha, and lint dependencies. Upstream fixes bound pathological expansion; public APIs and engine requirements are unchanged. Low risk; no direct brace-expansion declaration to remove.
Final state: MERGED at 2026-10-10T08:52:54Z; head 87b25c4; review APPROVED; merge state UNKNOWN after merge (CLEAN and MERGEABLE immediately before merge). CI: 9 successful, 0 failed, 0 pending; both required checks passed. Failure causality: none.
Actions taken: Verified base ancestry, complete diff, dependency tree with npm ls --package-lock-only, upstream patches, reviews, and current-head CI. Existing Linux/Windows/macOS CI passed lint, Java build, bundling, and extension tests; no local build or tests run. Approved audited head and squash-merged as 4aafc3b; mergedAt verified. No rebase, rerun, remediation, or push needed. Classic protection lookup returned 403; effective required checks and active branch rules were verified separately.
Reason: None
Next action: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant