github-action icon indicating copy to clipboard operation
github-action copied to clipboard

fix(deps): update brace-expansion

Open MikeMcC399 opened this issue 8 months ago • 1 comments

Situation

Dependabot and npm audit report a low severity vulnerability CVE-2025-5889 in a transient dependency:

used in action caching, action examples and ESLint related modules.

Lockfiles with vulnerable versions are:

Change

Update affected lock files to use:

MikeMcC399 avatar Jun 15 '25 08:06 MikeMcC399

cypress-app-bot avatar Jun 15 '25 08:06 cypress-app-bot

:tada: This PR is included in version 6.10.1 :tada:

The release is available on:

Your semantic-release bot :package::rocket:

github-actions[bot] avatar Jun 16 '25 13:06 github-actions[bot]