Skip to content

Fix CVE-2026-33750: bump brace-expansion 2.0.2 -> 2.0.3 - #704

Open
Jayanth Reddy Bujula (jbujula) wants to merge 1 commit into
mainfrom
users/jbujula/security-brace-expansion-cve-2026-33750
Open

Fix CVE-2026-33750: bump brace-expansion 2.0.2 -> 2.0.3#704
Jayanth Reddy Bujula (jbujula) wants to merge 1 commit into
mainfrom
users/jbujula/security-brace-expansion-cve-2026-33750

Conversation

@jbujula

Copy link
Copy Markdown
Collaborator

What

Bumps the pinned brace-expansion override from 2.0.2 to 2.0.3.

Why

Resolves the S360 [SFI-ES5.2] 1ES Open Source Vulnerabilities action item for Power Apps App Deployment (brace-expansion ReDoS, CVE-2026-33750). Matches the remediation already present in powerplatform-build-tools.

Validation

  • npm install -> lockfile resolves brace-expansion@2.0.3
  • npm run build passes
  • npm test passes (36 passing)

Only package.json and package-lock.json are changed.

Resolves the S360 [SFI-ES5.2] 1ES Open Source Vulnerabilities action item
for Power Apps App Deployment (brace-expansion ReDoS, CVE-2026-33750).
Matches the remediation already present in powerplatform-build-tools.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: de0407b8-fb71-416c-8f0c-d03c0a7e0ef7
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant