Commit 456bca6
fix(security): bump brace-expansion 2.x to 2.1.3 in root yarn.lock (#7063)
* fix(security): brace-expansion 2.x — lockfile re-resolution to 2.1.2
Resolves https://github.com/aws-amplify/amplify-ui/security/dependabot/565
(GHSA-3jxr-9vmj-r5cp / CVE-2026-13149): re-resolve the root yarn.lock
brace-expansion@^2.0.1/^2.0.2 block from 2.1.1 to patched 2.1.2.
Lockfile-only change; no package.json or resolutions edits.
The 1.x and 5.x blocks are intentionally untouched (alerts #564 / #561).
* fix(security): bump brace-expansion 2.x to 2.1.3
Re-resolve brace-expansion@^2.0.1/^2.0.2 from 2.1.2 to 2.1.3 in the
root yarn.lock. Lockfile-only change; no package.json edits needed.
---------
Co-authored-by: Pranav Malewadkar <7400617+pranavosu@users.noreply.github.com>
Co-authored-by: Michael Sober <msober@amazon.com>1 parent 733fd63 commit 456bca6
1 file changed
Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments