Skip to content

Patch brace-expansion vulnerability - #291

Merged
0xJem merged 2 commits into
developfrom
chore/brace-expansion-5-0-6
May 19, 2026
Merged

0xJem merged 2 commits into
developfrom
chore/brace-expansion-5-0-6

Conversation

@0xJem

@0xJem 0xJem commented May 19, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Add a pnpm workspace override for brace-expansion@>=5.0.0 <5.0.6 so vulnerable 5.0.5 resolves to patched 5.0.6.
  • Regenerate pnpm-lock.yaml for the patched transitive dependency path.
  • Remove the npx only-allow preinstall guard now that pnpm enforcement is handled through package manager metadata.

Validation

  • pnpm audit --audit-level moderate - no known vulnerabilities found
  • pnpm run lint - passed with existing warnings
  • pnpm build - passed with existing warnings
  • pnpm run lint:check - passed with existing warnings
  • pnpm run test:unit - passed, 191 suites / 2482 tests
  • coderabbit review --agent --base develop - 0 findings

Full pnpm run test was not run locally because this worktree has no .env and no ALCHEMY_API_KEY; shell/test_all.sh sources .env before running fork tests.

Summary by CodeRabbit

  • Chores
    • Removed the package manager validation script from the installation process.
    • Updated dependency version constraints for brace-expansion.

Review Change Stack

@coderabbitai

coderabbitai Bot commented May 19, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 79c4a02b-0b66-41de-8fc3-53660718c216

📥 Commits

Reviewing files that changed from the base of the PR and between 120266b and 6baf599.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (2)
  • package.json
  • pnpm-workspace.yaml
💤 Files with no reviewable changes (1)
  • package.json

📝 Walkthrough

Walkthrough

This PR removes the pnpm enforcement preinstall hook and updates the brace-expansion dependency override constraint in the workspace configuration. The preinstall script that prevented non-pnpm package managers from being used is deleted, and the brace-expansion version override is adjusted to target >=5.0.0 <5.0.6 with forced resolution to ^5.0.6.

Changes

Package Manager Configuration

Layer / File(s) Summary
pnpm enforcement removal and brace-expansion override
package.json, pnpm-workspace.yaml
The scripts.preinstall entry enforcing pnpm usage is removed from package.json, and the brace-expansion dependency override in pnpm-workspace.yaml is updated to target the >=5.0.0 <5.0.6 range with forced resolution to ^5.0.6.

Possibly related PRs

  • OlympusDAO/olympus-v3#226: Both PRs modify pnpm install hardening by adjusting only-allow/preinstall enforcement and brace-expansion version override constraints.

Suggested reviewers

  • zeroxnoodle

Poem

🐰 The pnpm lock unwinds, a softer touch,
brace-expansion gaps are closed as much,
No gatekeeping now—just deps that align,
Version constraints dance in perfect line! ✨


🎯 1 (Trivial) | ⏱️ ~2 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main change: patching a brace-expansion vulnerability via pnpm workspace overrides and removing the preinstall guard.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch chore/brace-expansion-5-0-6

Comment @coderabbitai help to get the list of available commands and usage tips.

@0xJem 0xJem self-assigned this May 19, 2026
@0xJem
0xJem requested a review from Yurii3721 May 19, 2026 13:05
@0xJem
0xJem merged commit ab021c3 into develop May 19, 2026
14 of 15 checks passed
@0xJem
0xJem deleted the chore/brace-expansion-5-0-6 branch May 19, 2026 14:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant