Skip to content

Commit 456bca6

Browse files
bobborpranavosusoberm
authored
fix(security): bump brace-expansion 2.x to 2.1.3 in root yarn.lock (#7063)
* fix(security): brace-expansion 2.x — lockfile re-resolution to 2.1.2 Resolves https://github.com/aws-amplify/amplify-ui/security/dependabot/565 (GHSA-3jxr-9vmj-r5cp / CVE-2026-13149): re-resolve the root yarn.lock brace-expansion@^2.0.1/^2.0.2 block from 2.1.1 to patched 2.1.2. Lockfile-only change; no package.json or resolutions edits. The 1.x and 5.x blocks are intentionally untouched (alerts #564 / #561). * fix(security): bump brace-expansion 2.x to 2.1.3 Re-resolve brace-expansion@^2.0.1/^2.0.2 from 2.1.2 to 2.1.3 in the root yarn.lock. Lockfile-only change; no package.json edits needed. --------- Co-authored-by: Pranav Malewadkar <7400617+pranavosu@users.noreply.github.com> Co-authored-by: Michael Sober <msober@amazon.com>
1 parent 733fd63 commit 456bca6

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

yarn.lock

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)