Skip to content

chore: Bump brace-expansion - #8736

Open
Steve-Mcl wants to merge 1 commit into
mainfrom
chore/bump-brace-expansion
Open

Steve-Mcl wants to merge 1 commit into
mainfrom
chore/bump-brace-expansion

Conversation

@Steve-Mcl

Copy link
Copy Markdown
Contributor

Description

Updates the 1.x, 2.x and 5.x copies in package-lock.json (1.1.21, 2.1.7, 5.0.12). All come in through dev tooling (eslint, mocha, nodemon, nyc, sentry and redocly), and the existing ranges already allow the fixed versions, so only the lockfile changes.

Steps (npm 11):

  • npm update brace-expansion (fixed the nested copies)
  • delete the top-level node_modules/brace-expansion entry from package-lock.json, which npm update left at 1.1.18
  • npm install (re-resolves it to 1.1.21)

Clears Trivy code scanning alerts 251-256 and 277-279.

Related Issue(s)

Trivy code scanning alerts 251-256 and 277-279.

Checklist

  • I have read the contribution guidelines
  • Suitable unit/system level tests have been added and they pass
  • Documentation has been updated
    • Upgrade instructions
    • Configuration details
    • Concepts
  • Changes flowforge.yml?
    • Issue/PR raised on FlowFuse/helm to update ConfigMap Template
    • Issue/PR raised on FlowFuse/CloudProject to update values for Staging/Production
  • Link to Changelog Entry PR, or note why one is not needed.

Labels

  • Includes a DB migration? -> add the area:migration label

Updates the 1.x, 2.x and 5.x copies in package-lock.json (1.1.21,
2.1.7, 5.0.12). All come in through dev tooling (eslint, mocha,
nodemon, nyc, sentry and redocly), and the existing ranges already
allow the fixed versions, so only the lockfile changes.

Steps (npm 11):
- npm update brace-expansion (fixed the nested copies)
- delete the top-level node_modules/brace-expansion entry from
  package-lock.json, which npm update left at 1.1.18
- npm install (re-resolves it to 1.1.21)

Clears Trivy code scanning alerts #251-#256 and #277-#279.
@codecov

codecov Bot commented Sep 30, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 77.61%. Comparing base (b6f6140) to head (256c05a).
⚠️ Report is 6 commits behind head on main.

Additional details and impacted files
@@            Coverage Diff             @@
##             main    #8736      +/-   ##
==========================================
+ Coverage   77.50%   77.61%   +0.10%     
==========================================
  Files         469      469              
  Lines       25356    25374      +18     
  Branches     6754     6760       +6     
==========================================
+ Hits        19652    19693      +41     
+ Misses       5704     5681      -23     
Flag Coverage Δ
backend 77.61% <ø> (+0.10%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch was successfully deployed

1 active deployment
staging — 256c05ab Deployed Sep 30, 2026 by Steve-Mcl via Deploy application #12032
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants