From 4024eb23b8d3d41d386eb74511104d9742ad4abb Mon Sep 17 00:00:00 2001 From: "warp-agent-staging[bot]" <240773466+warp-agent-staging[bot]@users.noreply.github.com> Date: Fri, 14 Aug 2026 16:29:52 +0000 Subject: [PATCH 1/2] fix(deps): patch brace-expansion DoS (GHSA-rgw5-rvv9-x895) Update the brace-expansion overrides to close both vulnerable copies left after the CVE-2026-14257 mitigation was found incomplete (GHSA-rgw5-rvv9-x895 / CVE-2026-69152): - brace-expansion@<1.1.18 -> 1.1.18 (pulled in by minimatch@^1.1.7, used by @eslint/eslintrc) - brace-expansion@>=3.0.0 <5.0.9 -> 5.0.9 (widened/bumped from the previous >=3.0.0 <5.0.7 -> 5.0.7 pin; pulled in by minimatch@^11, used by @typescript-eslint/typescript-estree) Both copies are dev-scope transitive dependencies with no production exposure. Regenerated package-lock.json via npm install. Ref: DEVX-8507 Co-Authored-By: Warp --- package-lock.json | 48 ++++++++++++++++++++++++++++++----------------- package.json | 3 ++- 2 files changed, 33 insertions(+), 18 deletions(-) diff --git a/package-lock.json b/package-lock.json index 4962783..1578178 100644 --- a/package-lock.json +++ b/package-lock.json @@ -48,6 +48,28 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/@emnapi/core": { + "version": "1.11.3", + "resolved": "https://registry.npmjs.org/@emnapi/core/-/core-1.11.3.tgz", + "integrity": "sha512-zLpS5asjEb7lq8jYLq37N6XKaE41DIexlY1rF/z4/tIl3wo13Sqm28fRyfIsKZD+NZ8mM5RoKkpW/rBcuoSZSg==", + "dev": true, + "license": "MIT", + "optional": true, + "dependencies": { + "@emnapi/wasi-threads": "1.2.3", + "tslib": "^2.4.0" + } + }, + "node_modules/@emnapi/runtime": { + "version": "1.11.3", + "resolved": "https://registry.npmjs.org/@emnapi/runtime/-/runtime-1.11.3.tgz", + "integrity": "sha512-Xz4Tpyki7XyrpbUK1jR1AhdAdaXyhhY4lZ3neLodmhpuWfy2PAQN5B46sAiU4liOXGLkHypn/qU+jvfWSCYYLA==", + "license": "MIT", + "optional": true, + "dependencies": { + "tslib": "^2.4.0" + } + }, "node_modules/@emnapi/wasi-threads": { "version": "1.2.3", "resolved": "https://registry.npmjs.org/@emnapi/wasi-threads/-/wasi-threads-1.2.3.tgz", @@ -1990,7 +2012,6 @@ "integrity": "sha512-V6Ar115dBDrjbtXSrS+/Oruobc+qVbbUxDFC1RSbRqLt5SYvxxyIDrSC85RWml54g+jfNeEMZhEj7wW07ONQhA==", "devOptional": true, "license": "MIT", - "peer": true, "dependencies": { "csstype": "^3.0.2" } @@ -2040,7 +2061,6 @@ "integrity": "sha512-CZ4nMxWwgu1HEEFNkeaCptra9QCtkmKdgf3sWh1rl1trIhmxLilgTV4cwcbQ4wemnT4sWQN8CaKOmdYx+g2gMA==", "dev": true, "license": "MIT", - "peer": true, "dependencies": { "@typescript-eslint/scope-manager": "8.65.0", "@typescript-eslint/types": "8.65.0", @@ -2195,9 +2215,9 @@ } }, "node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansion": { - "version": "5.0.8", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.8.tgz", - "integrity": "sha512-JZyDyq3D4AUifKTPOB7DELf6XsB3WdPuNxCtob1vFXPsSXhdAiHBWJ/tJ8HAc9aH84BK+5JFZLNkJKx3G9kzQg==", + "version": "5.0.9", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-5.0.9.tgz", + "integrity": "sha512-ScQ4IuvIEF1TMlP7Zt+vjJ//9zlPb2SDcxWxM3bk8s6t6GGdJ7KO1dCcTidOPJKePW30LE/2cT7wCyPho9/Wxg==", "dev": true, "license": "MIT", "dependencies": { @@ -2669,7 +2689,6 @@ "integrity": "sha512-xRQbDb9BnwDafYNn6Vwl839DYVjqXYb1XVGtWAZ1kcDc6iwAL4hg3B1dZlRiuENFeO2H53gFG3in621AdERVAg==", "dev": true, "license": "MIT", - "peer": true, "bin": { "acorn": "bin/acorn" }, @@ -2970,9 +2989,9 @@ "license": "MIT" }, "node_modules/brace-expansion": { - "version": "1.1.16", - "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.16.tgz", - "integrity": "sha512-IDw48K2/2kRkg9LdJxurvq3lV3aBgq0REY89duEqFRthjlPdXHKMj7EnQOXVckxzgisinf3nHfrcE2FufFLXMw==", + "version": "1.1.18", + "resolved": "https://registry.npmjs.org/brace-expansion/-/brace-expansion-1.1.18.tgz", + "integrity": "sha512-Edep/X9fGqVNmzKBVsDYIOtD+z1tuezV70LBjdCst9Tqu76lsnvRiZ6oTic1n+/BIwX6QDGAO94PN4N2SADvtw==", "dev": true, "license": "MIT", "dependencies": { @@ -3571,7 +3590,6 @@ "integrity": "sha512-DgZS62aPLXKlnxILS/AYCoRvHaZeXceIzlXPkkGGzJWSow1aEk0lbTlxUSlyjC8jcaKxAdOnTDz+o1JFSBsyjw==", "dev": true, "license": "MIT", - "peer": true, "dependencies": { "@eslint-community/eslint-utils": "^4.8.0", "@eslint-community/regexpp": "^4.12.1", @@ -3745,7 +3763,6 @@ "integrity": "sha512-whOE1HFo/qJDyX4SnXzP4N6zOWn79WhnCUY/iDR0mPfQZO8wcYE4JClzI2oZrhBnnMUCBCHZhO6VQyoBU95mZA==", "dev": true, "license": "MIT", - "peer": true, "dependencies": { "@rtsao/scc": "^1.1.0", "array-includes": "^3.1.9", @@ -5467,7 +5484,6 @@ "resolved": "https://registry.npmjs.org/next/-/next-15.5.22.tgz", "integrity": "sha512-mrtal1sRxO4YrlDS98sDuIvGZivKbFix8w7oAL9ZynfOgc3cADQOQgvwtMooc18Qr8bKzvQAcHwHZ0mbJ7zcfQ==", "license": "MIT", - "peer": true, "dependencies": { "@next/env": "15.5.22", "@swc/helpers": "0.5.15", @@ -6177,7 +6193,8 @@ "version": "0.27.0", "resolved": "https://registry.npmjs.org/scheduler/-/scheduler-0.27.0.tgz", "integrity": "sha512-eNv+WrVbKu1f3vbYJT/xtiF5syA5HPIMtf9IgY/nKg0sWqzAUEvqY/xm7OcZc/qafLx/iO9FgOmeSAp4v5ti/Q==", - "license": "MIT" + "license": "MIT", + "peer": true }, "node_modules/semver": { "version": "7.8.5", @@ -6630,8 +6647,7 @@ "version": "4.3.3", "resolved": "https://registry.npmjs.org/tailwindcss/-/tailwindcss-4.3.3.tgz", "integrity": "sha512-gOhV3P7ufE62QDGg1zVaTgCR+EtPv92k2nIhVcVKcLmxT1sUBsQGhnZj175j+MqRt4zLF7ic+sCYjfhxMxj7YQ==", - "license": "MIT", - "peer": true + "license": "MIT" }, "node_modules/tailwindcss-animate": { "version": "1.0.7", @@ -6697,7 +6713,6 @@ "integrity": "sha512-RvwwcruNjI1ncT5xRakeyS9Lf8lcItv34KD+aif+VH9kduAyfYBipGh12274xtenIPZ119/R9BdTBa8gAwSh0A==", "dev": true, "license": "MIT", - "peer": true, "engines": { "node": ">=12" }, @@ -6847,7 +6862,6 @@ "integrity": "sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==", "dev": true, "license": "Apache-2.0", - "peer": true, "bin": { "tsc": "bin/tsc", "tsserver": "bin/tsserver" diff --git a/package.json b/package.json index d61c41b..b5288bc 100644 --- a/package.json +++ b/package.json @@ -37,7 +37,8 @@ }, "overrides": { "postcss": "8.5.18", - "brace-expansion@>=3.0.0 <5.0.7": "5.0.7", + "brace-expansion@<1.1.18": "1.1.18", + "brace-expansion@>=3.0.0 <5.0.9": "5.0.9", "sharp": ">=0.35.0", "js-yaml": "4.3.1" } From 23b3d7fdd1566808a2bb1fc9ce9513ee3cdfe471 Mon Sep 17 00:00:00 2001 From: "warp-agent-staging[bot]" <240773466+warp-agent-staging[bot]@users.noreply.github.com> Date: Fri, 14 Aug 2026 16:40:37 +0000 Subject: [PATCH 2/2] fix(deps): map each brace-expansion major to its own patched version Address review findings on PR #26 for DEVX-8507 (GHSA-rgw5-rvv9-x895): - The previous >=3.0.0 <5.0.9 -> 5.0.9 override left the 2.x vulnerable range (>=2.0.0 <2.1.4) uncovered, and 5.0.9 falls outside normal 3.x/4.x consumer ranges so npm would not force it onto nested consumers requesting exact 3.x/4.x versions. - Replace it with one override per vulnerable major line, each mapped to that line's own first patched version, mirroring the advisory's range -> patch mapping exactly: brace-expansion@<1.1.18 -> 1.1.18 brace-expansion@>=2.0.0 <2.1.4 -> 2.1.4 brace-expansion@>=3.0.0 <3.0.6 -> 3.0.6 brace-expansion@>=4.0.0 <5.0.9 -> 5.0.9 - This also avoids forcing 3.x consumers onto the 5.x line, which narrows engine support (5.0.9 requires Node 20 || >=22, while 3.0.6/4.0.1 support Node >=18). Regenerated package-lock.json; resolved tree is unchanged for the two copies that actually exist (1.1.18, 5.0.9) confirming the new 2.x/3.x keys are inert against the current dependency tree. Ref: DEVX-8507 Co-Authored-By: Warp --- package.json | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/package.json b/package.json index b5288bc..f420274 100644 --- a/package.json +++ b/package.json @@ -38,7 +38,9 @@ "overrides": { "postcss": "8.5.18", "brace-expansion@<1.1.18": "1.1.18", - "brace-expansion@>=3.0.0 <5.0.9": "5.0.9", + "brace-expansion@>=2.0.0 <2.1.4": "2.1.4", + "brace-expansion@>=3.0.0 <3.0.6": "3.0.6", + "brace-expansion@>=4.0.0 <5.0.9": "5.0.9", "sharp": ">=0.35.0", "js-yaml": "4.3.1" }