Skip to content

Bump brace-expansion from 1.1.12 to 1.1.15 - #2824

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/brace-expansion-1.1.15
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/npm_and_yarn/brace-expansion-1.1.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 29, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.12 to 1.1.15.

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

Commits

Copilot AI review requested due to automatic review settings May 29, 2026 21:39
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript labels May 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/brace-expansion-1.1.15 branch from d3f5f2c to 2643fed Compare June 15, 2026 16:10
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.12 to 1.1.15.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v1.1.12...v1.1.15)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.15
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@piyalbasu

Copy link
Copy Markdown
Contributor

Superseded by #2849, which consolidates this bump along with the rest of the open npm/yarn dependabot PRs (built + tested: 1050 tests pass).

@piyalbasu piyalbasu closed this Jun 18, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jun 18, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/brace-expansion-1.1.15 branch June 18, 2026 16:28
piyalbasu added a commit that referenced this pull request Jun 18, 2026
Layers the four lockfile-only dependabot security/transitive bumps on top
of the #2843 minor-and-patch group merge, then runs `yarn dedupe`:

  joi             17.13.3 -> 17.13.4   (#2842)
  hono            4.11.8  -> 4.12.25   (#2837)
  shell-quote     1.8.3   -> 1.8.4     (#2836)
  brace-expansion 1.1.12  -> 1.1.15    (#2824)

hono is pinned to 4.12.25 (the dependabot target) rather than the
highest in-range 4.12.26.

js-yaml 4.1.1 -> 4.2.0 (#2847/#2848) is already included via the #2843
minor-and-patch group, so those two PRs are redundant.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants