Skip to content

Bump brace-expansion to 5.0.12 in cookbook project - #1212

Merged
stefangutica merged 1 commit into
developmentfrom
fix-cookbook-brace-expansion-audit
Sep 30, 2026
Merged

stefangutica merged 1 commit into
developmentfrom
fix-cookbook-brace-expansion-audit

Conversation

@stefangutica

Copy link
Copy Markdown
Contributor

Description of the pull request (what is new / what has changed)

The Cookbook TS verification workflow fails on every PR since two high advisories were published for brace-expansion 5.0.9, used by the cookbook project (@multiversx/sdk-dapp-ui > @stencil/react-output-target > ts-morph > minimatch):

This bumps brace-expansion to 5.0.12, which fixes both and the moderate GHSA-q2hr-2g5m-vwhr:

  • testing/cookbook-ts/project/package.json: the brace-expansion override goes from ^5.0.9 to ^5.0.12.
  • testing/cookbook-ts/project/package-lock.json: only the brace-expansion entry changes (version, resolved, integrity). 5.0.12 has the same dependencies and engines as 5.0.9.

Checked locally: node ./testing/cookbook-ts/audit-project.mjs passes (0 high, 0 critical), npm ci --dry-run accepts the lockfile, and ./testing/cookbook-ts-ci.sh passes, building all 61 cookbook projects.

Did you test the changes locally ?

  • yes
  • no

Did you regenerate static/llms.txt and static/llms-full.txt ? (happens at build time)

  • yes
  • no

Which category (categories) does this pull request belong to?

  • document new feature
  • update documentation that is not relevant anymore
  • add examples or more information about a component
  • fix grammar issues
  • other

@stefangutica
stefangutica merged commit 5c69d3f into development Sep 30, 2026
4 checks passed
@stefangutica
stefangutica deleted the fix-cookbook-brace-expansion-audit branch September 30, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants