Skip to content

Comments

EUREKA-860: brace-expansion to 1.1.12 fixing ReDoS CVE-2025-5889 (Sunflower)#68

Open
julianladisch wants to merge 1 commit intoR1-2025from
EUREKA-860
Open

EUREKA-860: brace-expansion to 1.1.12 fixing ReDoS CVE-2025-5889 (Sunflower)#68
julianladisch wants to merge 1 commit intoR1-2025from
EUREKA-860

Conversation

@julianladisch
Copy link

https://folio-org.atlassian.net/browse/EUREKA-860

Eureka Sunflower uses a vulnerable brace-expansion version (1.1.11): https://github.com/folio-org/platform-lsp/blob/R1-2025-csp-4/yarn.lock#L3866

Details:

Task: Bump brace-expansion from 1.1.11 to 1.1.12 in the Sunflower branch of platform-lsp.

@julianladisch julianladisch changed the title EUREKA-860: brace-expansion to 1.1.12 fixing ReDoS CVE-2025-5889 EUREKA-860: brace-expansion to 1.1.12 fixing ReDoS CVE-2025-5889 (Sunflower) Feb 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant