[Snyk] Security upgrade @vscode/vsce from 3.9.1 to 3.9.2 - #2065
[Snyk] Security upgrade @vscode/vsce from 3.9.1 to 3.9.2#2065anandgupta42 wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-BRACEEXPANSION-18512280
|
This is a patch version upgrade. The changes consist of dependency updates and internal build process fixes. There are no documented breaking changes or new features. Changes:
Source: GitHub Release Notes
|
|
Important Review skippedIgnore keyword(s) in the title. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review SummaryStatus: No Issues Found | Recommendation: Merge Clean Snyk dependency bump of Files Reviewed (2 files)
Reviewed by glm-5.2 · Input: 24.3K · Output: 3.6K · Cached: 239.4K Review guidance: REVIEW.md from base branch |
Bundle Size Reportdarwin-arm64: 75.7 MB
linux-x64: 77.6 MB
win32-x64: 78.0 MB
|
Snyk has created this PR to fix 1 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-BRACEEXPANSION-18512280
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling
Note
Low Risk
Patch-level dev/publish dependency bump with no runtime extension code changes; main residual risk is packaging/publish workflows if vsce behavior shifted.
Overview
Bumps
@vscode/vscefrom^3.9.1to^3.9.2inpackage.jsonand refreshespackage-lock.json. This is a dependency-only change aimed at addressing Snyk SNYK-JS-BRACEEXPANSION-18512280 (high severity resource-allocation issue in thebrace-expansionchain).The lockfile also reflects
@vscode/vsce’s updated transitive tree— notably newerglob(^13.0.6) andminimatch(^10.2.2/^10.2.6) undernode_modules/@vscode/vsce—with no application source changes.vsceremains the tool used forvsce package/vsce publishextension packaging.Reviewed by Cursor Bugbot for commit 4693b12. Bugbot is set up for automated code reviews on this repo. Configure here.