•  
      request #47551 brace-expansion: 1.1.12 -> 1.1.13, 2.0.2 -> 2.0.3, 5.0.3 -> 5.0.5
    Infos
    #47551
    Joris MASSON (jmasson)
    2026-03-27 17:45
    2026-03-27 15:43
    49274
    Details
    brace-expansion: 1.1.12 -> 1.1.13, 2.0.2 -> 2.0.3, 5.0.3 -> 5.0.5

    Fixes CVE-2026-33750, see the advisory: https://github.com/advisories/GHSA-f886-m6hf-6m8v

    It is only used in dev tools (jest, eslint, gettext extraction tool chain, vue3-gettext extractor that is never used) and the impact is overuse of memory and denial of service. Tuleap itself is not affected.

    Dev tools
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Joris MASSON (jmasson)
    Closed
    2026-03-27
    Attachments
    Empty
    References
    Referenced by request #47551

    Follow-ups