fix(deps): update brace-expansion security patches - #1460
Conversation
…kill-selection-0978
…kill-selection-0978
…kill-selection-0978
|
Warning Review limit reachedYou’ve reached a temporary PR review limit under our Fair Usage Limits Policy. Next review available in: 9 minutes Your organization has reached its usage spending cap. Adjust your spending cap in the billing tab. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
Comment |
|
Superseded by #1456. Both PRs apply the same |
…kill-selection-0978
|
@cursoragent this PR will be re-opened soon. Please resolve any failing CI, run bugbot and resolve any bugbot comments against current repo and fix any merge conflicts and also fix any errors and address and fix all comments or suggestions that are likely to improve the PR and Codebase. Please implement smallest required fix according to best code practices. Check your work. Leave this PR closed for now but still make all these changes and run the review. I want it ready to go for when I re-open it. |
|
PR #1460 is still closed. Branch tip What I found
What I did
Review verdictNo P0–P2 findings on the remaining unique diff. Reopen is conflict-free, but merge would be ledger-only unless you add new work — the security patch itself is already on |
Keep a clean append-only ledger delta after merging current main, where the brace-expansion product patch already landed via #1456. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Document that the branch is synced with main, Bugbot found nothing, and the brace-expansion product patch already landed through #1456. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
…kill-selection-0978 Sync closed PR #1460 once more before reopen; main advanced by one issues-ledger commit. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
|
This pull request has been ignored for the connected project Preview Branches by Supabase. |
|
@cursoragent Work this open PR (confirm number + GitHub head first). Start from Goal: review + Bugbot the tip, fix actionable issues with smallest changes,
Stop when merge-tree clean, no actionable threads left, and required checks are |
|
PR #1460 tip Done
Required CI on tip
|
…kill-selection-0978 Unblock PR #1460: GitHub reported DIRTY while merge-tree was behind-but-clean. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
…1460 Main already carried the 2026-07-30 ref/HEAD/scope row; keep the reopen- readiness note and record the post-sync review+bugbot+fix pass. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
Supersedes the prior same-scope row for the earlier merge tip after main advanced with #1521 mid-pass. Co-authored-by: BigSimmo <BigSimmo@users.noreply.github.com>
PR #1460 review+bugbot+fixTip: Snapshot / sync
Review + Bugbot
Fixed vs dispositioned
Required CI
Residual risks
|


Summary
brace-expansionoverride lines to patched releases: 1.1.18, 2.1.4, and 5.0.9RAG impact: no retrieval behaviour change — the PR diff is limited to dependency overrides, the npm lockfile, and the review ledger; protected RAG files are present only through current-main ancestry.
Verification
npm run verify:pr-localtests/ci-cache-safety.test.tsfailed from Windows Git-Bash multiline argument handling, and that file plus.github/workflows/ci.ymlare unchanged fromorigin/mainbrace-expansion@1.1.18npm audit --omit=dev— 0 vulnerabilitiesnpm run check:rag:fixtures— 36 golden cases / 21 suitesnpm run check:branch-review-ledgerUI verification not run: no UI, routing, styling, browser, reduced-motion, or forced-colors behavior changed.
Verification not run: local production build could not acquire the exclusive repository lock; hosted required build/checks must pass on this exact head before merge.
Risk and rollout
mainwill trigger the repository's normal Railway auto-deploy; no Supabase, OpenAI, hosted migration, or manual deployment action is included.Notes
maxLengthguard.