SIGN IN SIGN UP

fix(deps): runtime dependency security fixes (#24911)

## Summary

Batched **runtime** dependency security fixes. One commit per
vulnerability.

### Fixes

- `brace-expansion` 1.1.18 → 1.1.21 — GHSA-q2hr-2g5m-vwhr /
CVE-2026-102277 (medium) —
https://github.com/getsentry/sentry-javascript/security/dependabot/2599

### Notes

`brace-expansion` is not a direct dependency anywhere in the monorepo —
the only vulnerable instance was the `brace-expansion@^1.1.7` lockfile
entry pulled in via `minimatch@3.x`. That range already permits the
patched `1.1.21`, so this is a **lockfile-only re-resolution**: no
`package.json` change and no `resolutions` override.

Re-resolving the lockfile also moved two non-vulnerable entries forward
within their existing semver ranges:

- `brace-expansion@^2.0.1, ^2.0.2`: 2.0.2 → 2.1.7
- `brace-expansion@^5.0.5`: 5.0.6 → 5.0.12

`yarn dedupe-deps:check` passes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
J
javascript-sdk-gitflow[bot] committed
a0faac6b337df5fb756a34f5d74f2ed6f7b29e06
Parent: b45e5b8
Committed by GitHub <noreply@github.com> on 10/1/2026, 8:57:47 AM