Skip to content

fix(deps): vuln minor: shell-quote · patch: brace-expansion [tests/integration] - #850

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/integration/0-1786949237
Draft

fix(deps): vuln minor: shell-quote · patch: brace-expansion [tests/integration]#850
gh-worker-campaigns-3e9aa4[bot] wants to merge 2 commits into
mainfrom
engraver-auto-version-upgrade/minorpatch/npm/integration/0-1786949237

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: High-severity security update — 2 packages upgraded (MINOR changes included)

Manifests changed:

  • tests/integration (yarn)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

PackageFromToTypeDep TypeVulnerabilities Fixed
brace-expansion1.1.141.1.18patchTransitive6 HIGH
shell-quote1.8.41.10.0minorTransitive2 HIGH

Security Details

🚨 Critical & High Severity (8 fixed)
PackageCVESeveritySummaryUnsafe VersionFixed InCase
brace-expansionGHSA-rgw5-rvv9-x895HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation1.1.141.1.18-
brace-expansionCVE-2026-69152HIGHbrace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation1.1.14--
brace-expansionGHSA-mh99-v99m-4gvgHIGHbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash1.1.145.0.8-
brace-expansionCVE-2026-14257HIGHbrace-expansion DoS via unbounded expansion length causing an out-of-memory process crash1.1.14--
brace-expansionGHSA-3jxr-9vmj-r5cpHIGHbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups1.1.145.0.7-
brace-expansionCVE-2026-13149HIGH-1.1.14--
shell-quoteGHSA-395f-4hp3-45gvHIGHshell-quote: Quadratic-complexity Denial of Service in parse() (CWE-407)1.8.41.9.0-
shell-quoteCVE-2026-13311HIGHshell-quote parse() is quadratic in token count, enabling denial of service1.8.4--

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-5

datadog-prod-us1-5Bot commented Aug 17, 2026

Copy link
Copy Markdown

Pipelines

⚠️ Warnings

🚦 1 Pipeline job failed

DataDog/datadog-lambda-python | publish-layer-sandbox (python313-amd64): [us-west-2]

View in Datadog · View in GitLab

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: 12bdb4a | Docs | View more details | Give us feedback!

dd-octo-sts-c33ac5Botand others added 2 commits August 18, 2026 18:20
…tion]
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
Co-authored-by: gh-worker-campaigns-3e9aa4[bot] <244854796+gh-worker-campaigns-3e9aa4[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
ContributorAuthor

Auto-rebase complete

Branch is up to date with main — rebased onto c0b98d6.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-c33ac5
dd-octo-sts-c33ac5Botforce-pushed the engraver-auto-version-upgrade/minorpatch/npm/integration/0-1786949237 branch from 810dc6a to 12bdb4aCompareAugust 18, 2026 18:20
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants