Skip to content

fix(deps): clear brace-expansion and axios advisories - #648

Merged
cline-cloud[bot] merged 2 commits into
mainfrom
security/brace-expansion-5.0.12
Oct 1, 2026
Merged

cline-cloud[bot] merged 2 commits into
mainfrom
security/brace-expansion-5.0.12

Conversation

@cline-cloud

@cline-cloud cline-cloud Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Why

Two web/package.json overrides were resolving into vulnerable ranges, and
between them were the only reason Dependency Audit was red:

Package Was Now
brace-expansion 5.0.9 5.0.12
axios >=1.18.0 (resolved 1.18.1) ^1.19.1 (resolved 1.20.0)

Cleared by the brace-expansion bump:

Cleared by the axios bump: 12 advisories against 1.0.0 - 1.19.0, including
prototype pollution, header injection, and redirect-based SSRF.

axios is reachable only through wait-on, a devDependency that requires
^1.18.1, so 1.20.0 stays compatible.

Verification

  • npm ci -> exit 0
  • npm audit --audit-level=high -> 0 vulnerabilities
  • npm test -> 18 test files, 175 tests passed
  • Lockfile integrity hashes for both packages match the npm registry

Scope

The brace-expansion bump was split out of #647, where it sat under a docs:
title. The axios bump is a pre-existing failure on main (Security Scan has
been red since 2026-09-13) and was the last high-severity finding, so it is
folded in here rather than left as a separate follow-up.

@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
do-web-doc-resolover Ready Ready Preview Oct 1, 2026 4:35pm UTC

@codacy-production

Copy link
Copy Markdown
Contributor

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity

Metric Results
Complexity 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

The web override pinned axios to >=1.18.0, which resolved to 1.18.1, inside
the vulnerable 1.0.0-1.19.0 range flagged by npm audit --audit-level=high.
That failure is pre-existing on main (Security Scan red since 2026-09-13)
and was the only remaining high-severity finding.

axios is reachable only via wait-on, a devDependency that requires ^1.18.1,
so ^1.19.1 (resolving to 1.20.0) stays compatible.

Verified: npm ci exit 0; npm audit --audit-level=high -> 0 vulnerabilities;
npm test -> 18 files, 175 tests passing.

Refs #648
@cline-cloud cline-cloud Bot changed the title fix(deps): bump brace-expansion override to 5.0.12 fix(deps): clear brace-expansion and axios advisories Oct 1, 2026
@cline-cloud
cline-cloud Bot merged commit ccb7420 into main Oct 1, 2026
47 checks passed
@cline-cloud
cline-cloud Bot deleted the security/brace-expansion-5.0.12 branch October 1, 2026 16:47
cline-cloud Bot pushed a commit that referenced this pull request Oct 1, 2026
* docs: update human-facing docs and AGENTS.md workflow

* fix(deps): update brace-expansion to resolve dependency audit vulnerability

* chore(deps): move brace-expansion bump to its own PR (#648)

* docs: complete AGENTS.md index tables and add README ToC

AGENTS.md listed 4 of the 16 documents in agents-docs/ and 5 of the 16
skills in .agents/skills/. Both tables are now complete, with
descriptions taken from each skill's own frontmatter.

README.md is 178 lines with 19 headings and had no Table of Contents,
which readme-best-practices flags as a defect for READMEs over 100
lines. Anchors for the repeated "Rust CLI (do-wdr)" and "Web UI"
headings use the -1 suffix GitHub generates.

markdownlint-cli2: 0 issues.

Refs #647

* fix(deps): update axios and package-lock to resolve npm audit vulnerability

---------

Co-authored-by: d-oit <dominik.oswald@example.com>

This branch was successfully deployed

1 active deployment
Preview — d34ae4bc Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant