mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
chore(ui): update dependency brace-expansion@>=5 to v5.0.12 [security]
This commit is contained in:
@@ -1,6 +1,3 @@
|
||||
# pnpm 11+ workspace config. .npmrc is auth/registry only; everything else lives here.
|
||||
# Reference: https://pnpm.io/supply-chain-security
|
||||
|
||||
packages: []
|
||||
|
||||
# Refuse to install on Node/pnpm outside the `engines` block in package.json.
|
||||
@@ -93,7 +90,7 @@ overrides:
|
||||
# expansion length OOM, unbounded intermediate arrays bypassing the
|
||||
# CVE-2026-14257 mitigation). 1.x via eslint > minimatch, 5.x via @sentry > glob.
|
||||
"brace-expansion@<2": "1.1.18"
|
||||
"brace-expansion@>=5": "5.0.9"
|
||||
"brace-expansion@>=5": "5.0.12"
|
||||
# fast-uri (via ajv): host confusion through backslash authority delimiters,
|
||||
# failed IDN canonicalization and percent-encoded scheme normalization, plus SSRF
|
||||
# via malformed IPv6 normalization and repeated hostname percent-decoding.
|
||||
@@ -157,3 +154,6 @@ trustPolicyExclude:
|
||||
|
||||
# Block transitive dependencies from using exotic specifiers (git URLs, tarballs).
|
||||
blockExoticSubdeps: true
|
||||
minimumReleaseAgeExclude:
|
||||
# Renovate security update: brace-expansion@5.0.12
|
||||
- brace-expansion@5.0.12
|
||||
|
||||
Reference in New Issue
Block a user