fix(deps): runtime dependency security fixes (#24911)
## Summary Batched **runtime** dependency security fixes. One commit per vulnerability. ### Fixes - `brace-expansion` 1.1.18 → 1.1.21 — GHSA-q2hr-2g5m-vwhr / CVE-2026-102277 (medium) — https://github.com/getsentry/sentry-javascript/security/dependabot/2599 ### Notes `brace-expansion` is not a direct dependency anywhere in the monorepo — the only vulnerable instance was the `brace-expansion@^1.1.7` lockfile entry pulled in via `minimatch@3.x`. That range already permits the patched `1.1.21`, so this is a **lockfile-only re-resolution**: no `package.json` change and no `resolutions` override. Re-resolving the lockfile also moved two non-vulnerable entries forward within their existing semver ranges: - `brace-expansion@^2.0.1, ^2.0.2`: 2.0.2 → 2.1.7 - `brace-expansion@^5.0.5`: 5.0.6 → 5.0.12 `yarn dedupe-deps:check` passes. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
J
javascript-sdk-gitflow[bot] committed
a0faac6b337df5fb756a34f5d74f2ed6f7b29e06
Parent: b45e5b8
Committed by GitHub <noreply@github.com>
on 10/1/2026, 8:57:47 AM