Remove vendored braces once upstream publishes a patched release #563

Open
opened 2026-10-04 18:21:57 +01:00 by Smithy-bot · 0 comments
Member

Parent: #531 (0.11.0 Dependency Updates)

Summary

#531 vendors a temporary [email protected] backport under vendor/braces (from micromatch/braces#72) because GHSA-vfj7-8cjw-p6xm / CVE-2026-93687 has no official npm release yet (latest is 3.0.3).

Work

When upstream publishes a fixed braces version:

  1. Remove vendor/braces/
  2. Remove the "braces": "file:./vendor/braces" resolution from package.json
  3. Reinstall and confirm yarn audit is still clean

Acceptance Criteria

  • Official patched braces is used from npm
  • Vendored copy and resolution are removed
  • yarn audit reports 0 vulnerabilities
Parent: #531 (0.11.0 Dependency Updates) ## Summary #531 vendors a temporary `[email protected]` backport under `vendor/braces` (from [micromatch/braces#72](https://github.com/micromatch/braces/pull/72)) because [GHSA-vfj7-8cjw-p6xm](https://github.com/advisories/GHSA-vfj7-8cjw-p6xm) / CVE-2026-93687 has no official npm release yet (latest is `3.0.3`). ## Work When upstream publishes a fixed `braces` version: 1. Remove `vendor/braces/` 2. Remove the `"braces": "file:./vendor/braces"` resolution from `package.json` 3. Reinstall and confirm `yarn audit` is still clean ## Acceptance Criteria - [ ] Official patched `braces` is used from npm - [ ] Vendored copy and resolution are removed - [ ] `yarn audit` reports 0 vulnerabilities
Smithy-bot added this to the 0.11.0 milestone 2026-10-04 18:21:57 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
External/card-drop#563
No description provided.