Skip to content

chore(deps): bump brace-expansion from 1.1.14 to 1.1.18 in /test-projects/expo-purchasely-test - #271

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/brace-expansion-1.1.18
Closed

chore(deps): bump brace-expansion from 1.1.14 to 1.1.18 in /test-projects/expo-purchasely-test#271
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/test-projects/expo-purchasely-test/brace-expansion-1.1.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps brace-expansion from 1.1.14 to 1.1.18.

Release notes

Sourced from brace-expansion's releases.

v1.1.15

  • Backport v5.0.6 change to v1 (#111) 0b09384

juliangruber/brace-expansion@v1.1.14...v1.1.15

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion) from 1.1.14 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](https://github.com/juliangruber/brace-expansion/commits)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Aug 3, 2026
@greptile-apps

greptile-apps Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

PR author is in the excluded authors list.

Copy link
Copy Markdown

Dependabot review — 2026-08-04 (research only, no merge/approve action taken)

Tracking summary for all 4 currently open Dependabot PRs posted on #269: #269 (comment) (Issues are disabled on this repo, so a PR comment hosts the summary instead of a GitHub issue).

This PR: brace-expansion 1.1.14 → 1.1.18 (patch). CI: build-ios failing while the other 6 checks (including the parallel build-rn-0-86-ios) are green. No merge conflicts, no hold label. Not auto-merging pending confirmation the build-ios failure is unrelated/flaky. Nothing merges until a human approves on the #269 tracking comment.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-08-08) is posted on #269 (GitHub Issues are disabled on this repo) — covers this PR plus #272, #273, #274, #269. This PR: brace-expansion 1.1.14 → 1.1.18 (patch, likely the GHSA-mh99-v99m-4gvg ReDoS backport), CI red on build-ios only (6/7 pass). See #269 for the full table and next steps — nothing merges without a human go-ahead there.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot triage tracking note for this cycle (2026-08-09) is posted on #269 (GitHub Issues are still disabled on this repo) — covers this PR plus #272, #273, #274, #269. This PR: brace-expansion 1.1.14 → 1.1.18 (patch, likely the GHSA-mh99-v99m-4gvg ReDoS backport), CI red on build-ios only (6/7 pass). See #269 for the full table and next steps — nothing merges without a human go-ahead there.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot PR Review — 2026-08-12 (research only, no merge/approve/rebase action taken)

Old tracking host #269 was closed (superseded by Dependabot itself when it opened #276) on 2026-08-11, so this comment on #271 — the oldest still-open PR in the batch — is now the tracking host. GitHub Issues are disabled on this repo, so a PR comment hosts the summary instead of a GitHub issue (same workaround used since 2026-08-04).

Current batch (7 open Dependabot PRs)

# Package Version Change Bump CI Action
#277 nanoid 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked (see root cause below)
#276 postcss (test-projects) 8.5.12→8.5.26 minor 🔴 build-ios only (6/7 pass) Supersedes closed #269. Auto-merge candidate once unblocked
#275 nanoid (test-projects) 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#274 undici (root) 7.28.0→7.29.0 minor — 5 CVE fixes (cache poisoning, header CRLF injection, content-length desync, cookie injection) 🔴 all 7 checks failing — the outlier, unchanged since its 2026-08-04 run Needs a fresh CI run (rebase) to see if it's just the same build-ios issue as the others or a real regression. Prioritize once green — genuine security content
#273 undici (test-projects) 8.5.0→8.10.0 minor 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#272 fast-uri (test-projects) 4.1.1→4.1.2 patch — security advisory GHSA-7p8r-x3mc-p8w7 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked
#271 (this PR) brace-expansion (test-projects) 1.1.14→1.1.18 patch — likely GHSA-mh99-v99m-4gvg ReDoS backport 🔴 build-ios only (6/7 pass) Auto-merge candidate once unblocked

No merge conflicts on any of the 7 (mergeable_state: blocked throughout, never dirty). No hold labels. All 7 bumps are minor/patch — no majors in this batch.

Root cause of the shared build-ios failure — and the fix is already open

Every PR above fails build-ios for the identical reason: Xcode 26's "Explicitly Built Modules" build setting can't resolve the plain #import "react_native_purchasely-Swift.h" in PurchaselyRN.m as a dependency edge on the pod's own module, so the Swift compile isn't guaranteed to run first — 'react_native_purchasely-Swift.h' file not found.

PR #278 (open, unmerged, from @AurelienV-42) fixes exactly this by switching to a module-qualified #import <react_native_purchasely/react_native_purchasely-Swift.h> guarded by __has_include. Verified against a real Xcode 26 build per the PR description.

Recommendation: merge #278 first, then ·@·d·ependabot r·ebase (or let the next auto-rebase cycle handle it) on the 7 PRs above. Expect all of them except possibly #274 to go fully green and become clean auto-merge candidates — several carry real security fixes (undici, fast-uri, brace-expansion).

Nothing merged, approved, rebased, or closed this cycle — waiting on an explicit human go-ahead on this comment before any action. cc @kherembourg @romainsalles


Generated by Claude Code

Copy link
Copy Markdown

Dependabot review — 2026-08-13: 7 open PRs, action plan

Automated Dependabot review (scheduled). This repo has GitHub Issues disabled, so I'm using this PR thread (the oldest in the batch) as the confirmation gate instead of a tracking issue. No PRs have been merged, approved, or commented on otherwise — nothing happens until someone confirms here. cc @kherembourg (most recently active non-bot contributor on this repo) — could you take a look?

Summary

# Package Scope Version change Bump CI Action
#277 nanoid root 3.3.11 → 3.3.18 patch 🔴 red (build-ios only, 6/7 green) CI failing
#276 postcss test-projects/expo-purchasely-test 8.5.12 → 8.5.26 patch 🔴 red (build-ios only, 6/7 green) CI failing
#275 nanoid test-projects/expo-purchasely-test 3.3.11 → 3.3.18 patch 🔴 red (build-ios only, 6/7 green) CI failing
#274 undici root 7.28.0 → 7.29.0 minor (security) 🔴 red (all 7 checks) CI failing
#273 undici test-projects/expo-purchasely-test 8.5.0 → 8.10.0 minor (security) 🔴 red (build-ios only, 6/7 green) CI failing
#272 fast-uri test-projects/expo-purchasely-test 4.1.1 → 4.1.2 patch (security) 🔴 red (build-ios only, 6/7 green) CI failing
#271 (this PR) brace-expansion test-projects/expo-purchasely-test 1.1.14 → 1.1.18 patch 🔴 red (build-ios only, 6/7 green) CI failing

No major bumps in this batch. All 7 report mergeable_state: blocked (not GitHub's dirty/conflict state) and none carry a hold/wip label — CI is the only thing blocking every one of these.

Notable pattern: shared build-ios failure

6 of 7 PRs fail only on build-ios, with every other check (build-android, build-rn-0-86-ios, build-rn-0-86-android, test, lint, iOS unit tests) green. This strongly suggests a single pre-existing iOS build issue unrelated to any of these dependency bumps, rather than each bump independently breaking iOS. #274 (undici root) is the outlier — all 7 checks fail there, which may be a separate, real issue with that bump specifically (or simply a stale run — it was queued 2026-08-04 while the PR shows "updated" 2026-08-12, likely just Dependabot's rebase-check comment rather than a fresh CI run).

Priority once CI is unblocked

Proposed plan (pending confirmation)

  1. Investigate the shared build-ios failure — fixing the root cause would very likely unblock 6 of these 7 PRs at once.
  2. Separately check chore(deps): bump undici from 7.28.0 to 7.29.0 #274's full-red run — confirm whether it's a stale run needing a rebase/re-trigger, or a real break from the undici 7.29.0 bump.
  3. Once CI is green, merge in priority order: chore(deps): bump undici from 7.28.0 to 7.29.0 #274, chore(deps): bump undici from 8.5.0 to 8.10.0 in /test-projects/expo-purchasely-test #273, chore(deps): bump fast-uri from 4.1.1 to 4.1.2 in /test-projects/expo-purchasely-test #272 (security-relevant) first, then the remaining patch bumps.

Reply here to confirm this plan, or let me know if you'd rather I just trigger reruns/rebases first and reassess.


Generated by Claude Code

Copy link
Copy Markdown

Dependabot review — 2026-08-17 (first pass for this repo). GitHub Issues are disabled on this repo, so this PR comment is standing in as the confirmation-gate thread for all 7 currently open Dependabot PRs — nothing gets merged until a human replies here (or on the individual PR) with a go-ahead.

Summary

# Package Version change Bump CI Action
#277 nanoid 3.3.11→3.3.18 patch 🔴 build-ios failing (all else green) CI Failing — see shared pattern below
#276 postcss (/test-projects/expo-purchasely-test) 8.5.12→8.5.26 minor 🔴 build-ios failing (all else green) CI Failing — see shared pattern below
#275 nanoid (/test-projects/expo-purchasely-test) 3.3.11→3.3.18 patch 🔴 build-ios failing (all else green) CI Failing — see shared pattern below
#274 undici 7.28.0→7.29.0 patch 🔴 all 7 jobs failing (lint, test, build-android/ios, build-rn-0-86-android/ios, iOS Unit Tests) CI Failing — worse than the others, needs its own look
#273 undici (/test-projects/expo-purchasely-test) 8.5.0→8.10.0 minor 🔴 build-ios failing (all else green) CI Failing — see shared pattern below
#272 fast-uri (/test-projects/expo-purchasely-test) 4.1.1→4.1.2 patch 🔴 build-ios failing (all else green) CI Failing — see shared pattern below
#271 (this PR) brace-expansion (/test-projects/expo-purchasely-test) 1.1.14→1.1.18 patch 🔴 build-ios failing (all else green) CI Failing — see shared pattern below

No hold labels on any of the 7.

Notable pattern: shared build-ios failure

Six of the seven (#277, #276, #275, #273, #272, this PR) fail on exactly one job — build-ios — with every other job green (lint, test, build-android, build-rn-0-86-android, build-rn-0-86-ios, iOS Unit Tests). This spans unrelated packages (nanoid, postcss, undici, fast-uri, brace-expansion) across both the main package and /test-projects/expo-purchasely-test, dating back to 2026-08-03 — strongly suggests a base-branch/toolchain issue rather than anything these bumps caused. Worth root-causing once rather than as six separate investigations. None of these six would otherwise be blocked: all patch/minor, no breaking-change signal expected.

#274 is a separate, worse case — every job fails, not just build-ios. It's also the oldest of the batch (2026-08-04) — may just need a Dependabot rebase against current main, or the plain undici 7.29.0 bump broke something the test-projects copy (#273, bumping to a different undici major line, 8.x) didn't hit.

Proposed plan (pending confirmation)

  1. Investigate the shared build-ios failure — once fixed, chore(deps): bump nanoid from 3.3.11 to 3.3.18 #277/chore(deps): bump postcss from 8.5.12 to 8.5.26 in /test-projects/expo-purchasely-test #276/chore(deps): bump nanoid from 3.3.11 to 3.3.18 in /test-projects/expo-purchasely-test #275/chore(deps): bump undici from 8.5.0 to 8.10.0 in /test-projects/expo-purchasely-test #273/chore(deps): bump fast-uri from 4.1.1 to 4.1.2 in /test-projects/expo-purchasely-test #272/this PR all become clean auto-merge candidates.
  2. Separately check chore(deps): bump undici from 7.28.0 to 7.29.0 #274 (rebase, or a real regression).
  3. No major-version bumps in this batch, so no changelog deep-dive needed.

Reply here (or on this issue... this PR) to confirm, adjust, or override.


Generated by Claude Code

Copy link
Copy Markdown

Update (2026-08-20 cycle) — fully unchanged, no merges/approvals taken.

Re-verified the batch via fresh get_check_runs on the two ends of the pattern (#277, #274) — same run IDs/timestamps as the 2026-08-17 snapshot, no new commits on any of the 7 since 2026-08-11/12. GitHub Issues are still disabled on this repo, so this PR thread remains the confirmation-gate host.

# Package Version change Bump CI Action
#277 nanoid 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 green) CI Failing — shared root cause below
#276 postcss (test-projects) 8.5.12→8.5.26 minor 🔴 build-ios only (6/7 green) CI Failing — shared root cause below
#275 nanoid (test-projects) 3.3.11→3.3.18 patch 🔴 build-ios only (6/7 green) CI Failing — shared root cause below
#274 undici 7.28.0→7.29.0 minor (5 CVE fixes) 🔴 all 7 jobs failing — the outlier, unchanged since 2026-08-04 CI Failing — needs its own look, prioritize once green (real security content)
#273 undici (test-projects) 8.5.0→8.10.0 minor (security) 🔴 build-ios only (6/7 green) CI Failing — shared root cause below
#272 fast-uri (test-projects) 4.1.1→4.1.2 patch (security, GHSA-7p8r-x3mc-p8w7) 🔴 build-ios only (6/7 green) CI Failing — shared root cause below
#271 (this PR) brace-expansion (test-projects) 1.1.14→1.1.18 patch (likely GHSA-mh99-v99m-4gvg) 🔴 build-ios only (6/7 green) CI Failing — shared root cause below

No hold labels, no merge conflicts on any of the 7. No majors in this batch.

Root cause still unfixed: #278 (the Xcode 26 explicit-modules #import fix, from @AurelienV-42) is still open and unmerged — same state since 2026-08-11. Merging it should unblock #277/#276/#275/#273/#272/#271 in one shot; #274 needs a separate look regardless.

No human comment has landed on this thread since 2026-08-17 (or on this whole batch since it started 2026-08-04) — zero response. Nothing merged, approved, rebased, or closed this cycle. cc @kherembourg @romainsalles — could someone confirm merging #278, and/or give a go-ahead on the security-relevant #274/#273/#272 once CI is unblocked?


Generated by Claude Code

@dependabot @github

dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown
Contributor Author

Looks like brace-expansion is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 20, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/test-projects/expo-purchasely-test/brace-expansion-1.1.18 branch August 20, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant