Skip to content

chore(deps): bump brace-expansion from 1.1.11 to 1.1.21 in /frontend - #2850

Merged
osmontero merged 2 commits into
v11from
dependabot/npm_and_yarn/frontend/brace-expansion-1.1.21
Oct 8, 2026
Merged

osmontero merged 2 commits into
v11from
dependabot/npm_and_yarn/frontend/brace-expansion-1.1.21

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.11 to 1.1.21.

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

v1.1.12

  • pkg: publish on tag 1.x c460dbd
  • fmt ccb8ac6
  • Fix potential ReDoS Vulnerability or Inefficient Regular Expression (#65) c3c73c8

juliangruber/brace-expansion@v1.1.11...v1.1.12

Commits

@dependabot
dependabot Bot requested a review from a team October 7, 2026 14:49
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 7, 2026
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.11 to 1.1.21.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@1.1.11...v1.1.21)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.21
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/frontend/brace-expansion-1.1.21 branch from 615f64b to 92e4e02 Compare October 8, 2026 16:34
@osmontero
osmontero merged commit 693ff9c into v11 Oct 8, 2026
2 checks passed
@osmontero
osmontero deleted the dependabot/npm_and_yarn/frontend/brace-expansion-1.1.21 branch October 8, 2026 16:37
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

❌ Go dependencies check failed

There are outdated Go dependencies, or modules that could not be inspected.
Run bash .github/scripts/go-deps.sh --update --discover locally and
commit the updated go.mod / go.sum files.

Script output
🔍 Discovered 25 Go projects

📦 Dependencies with updates available:

  📁 ./plugins/gcp:
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/aws:
     - github.com/aws/aws-sdk-go-v2: v1.47.0 → v1.47.1
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.7
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.7
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.1

  📁 ./plugins/alerts:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/events:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./plugins/modules-config:
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2
     - github.com/aws/aws-sdk-go-v2/config: v1.33.5 → v1.33.7
     - github.com/aws/aws-sdk-go-v2/credentials: v1.20.5 → v1.20.7
     - github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs: v1.88.0 → v1.89.1
     - github.com/aws/aws-sdk-go-v2/service/sts: v1.51.0 → v1.51.2
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0
     - google.golang.org/api: v0.299.0 → v0.301.0

  📁 ./plugins/azure:
     - github.com/Azure/azure-sdk-for-go/sdk/azcore: v1.23.1 → v1.23.3
     - github.com/Azure/azure-sdk-for-go/sdk/storage/azblob: v1.8.1 → v1.8.2

  📁 ./plugins/crowdstrike:
     - github.com/crowdstrike/gofalcon: v0.22.0 → v0.23.0

  📁 ./plugins/geolocation:
     - github.com/tidwall/gjson: v1.19.0 → v1.20.0

  📁 ./agent:
     - github.com/netsampler/goflow2: v1.3.7 → v1.3.8

�[0;31m❌ Please update dependencies before merging.�[0m

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

✅ AI review — Approved

No issues detected in this diff.

✅ architecture (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

✅ bugs (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

✅ security (silas-1.7-pro) — clean

Summary: No reviewable changes in this diff (excluded paths only).

No findings.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

⛔ Permission denied

Only members of @utmstack/administrators or @utmstack/core-developers can merge PRs into this repository.

PR author: @dependabot[bot]

The comments above (deps + AI review) are still valid — if you address them, the checks will re-run automatically, but final approval is left to an administrator.

@utmstack/administrators please review.

@utmstackprapprover utmstackprapprover Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Author is not in @utmstack/administrators nor @utmstack/core-developers — admin review required.

osmontero added a commit that referenced this pull request Oct 8, 2026
…build

The six frontend dependabot bumps (#2848, #2849, #2850, #2851, #2852, #2853)
re-resolved package-lock.json from lockfileVersion 1 to 3, dragging in
incompatible transitive deps (@types/node 8→18, echarts 4.9→3.8.5, moment
2.29→2.31) that the Angular 7 / TS 3.2 / Node 14 stack cannot compile.

Reverts frontend/package.json + package-lock.json to the last known-good
state (800dede). The backend/Go dependabot bumps (snakeyaml 2.0, gRPC
1.83.2, OTel 1.45.0) are fine — they don't affect the frontend build.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant