Repository navigation
Comparing changes
Open a pull request
base repository: juliangruber/brace-expansion
base: v1.1.12
head repository: juliangruber/brace-expansion
compare: v1.1.18
- 15 commits
- 12 files changed
- 8 contributors
Commits on Mar 27, 2026
-
Configuration menu - View commit details
-
Copy full SHA for 7fd684f - Browse repository at this point
Copy the full SHA 7fd684fView commit details -
Configuration menu - View commit details
-
Copy full SHA for 6c353ca - Browse repository at this point
Copy the full SHA 6c353caView commit details
Commits on Apr 4, 2026
-
Backport fix for GHSA-7h2j-956f-4vf2 to v1 (#101)
Co-authored-by: Victorino Machava <victorino.machava@vm.co.mz>
Configuration menu - View commit details
-
Copy full SHA for 0d7652e - Browse repository at this point
Copy the full SHA 0d7652eView commit details -
Revert "Backport fix for GHSA-7h2j-956f-4vf2 to v1 (#101)" (#102)
This reverts commit 0d7652e.
Configuration menu - View commit details
-
Copy full SHA for 2fbb6a2 - Browse repository at this point
Copy the full SHA 2fbb6a2View commit details
Commits on Apr 11, 2026
-
Add opt-in { max } mitigation to v1 legacy line (#103)
* Backport fix for GHSA-7h2j-956f-4vf2 to v1 * Remove `EXPANSION_MAX` and default to unbounded expansion --------- Co-authored-by: Victorino Machava <victorino.machava@vm.co.mz>
Configuration menu - View commit details
-
Copy full SHA for 1afa1b2 - Browse repository at this point
Copy the full SHA 1afa1b2View commit details -
Configuration menu - View commit details
-
Copy full SHA for 10c05fc - Browse repository at this point
Copy the full SHA 10c05fcView commit details
Commits on May 26, 2026
-
Backport v5.0.6 change to v1 (#111)
Co-authored-by: Siddharth Srinivasan <175113207+sid-srini@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0b09384 - Browse repository at this point
Copy the full SHA 0b09384View commit details -
Configuration menu - View commit details
-
Copy full SHA for 2203f4f - Browse repository at this point
Copy the full SHA 2203f4fView commit details
Commits on Jul 8, 2026
-
fix: v1 backport for CVE-2026-13149 (#122)
* fix: backport for CVE-2026-13149 * fix: backport for CVE-2026-13149 * Consistency with v5 patch * Consistency with v5 patch * Consistency with v5 patch * Update test/unbound-recursion.js * Update test/unbound-recursion.js --------- Co-authored-by: Julian Gruber <julian@juliangruber.com>
Configuration menu - View commit details
-
Copy full SHA for d74e630 - Browse repository at this point
Copy the full SHA d74e630View commit details -
Configuration menu - View commit details
-
Copy full SHA for 447763a - Browse repository at this point
Copy the full SHA 447763aView commit details
Commits on Jul 29, 2026
-
fix: backport GHSA-mh99-v99m-4gvg (#129)
* fix: default to a `max` of `100000` * fix: backport GHSA-mh99-v99m-4gvg * test: adopt the bounded default max on v1 The backport changes the default `max` from `Infinity` to `EXPANSION_MAX` (100,000), matching v5. `test/sequence.js` still asserted the old unbounded behaviour, so the suite was red. Update both assertions to the capped default and add a single-sequence case exercising the cap. Otherwise keep 1.x's observable behaviour untouched, so this ships the vulnerability fixes and nothing else. Two places had drifted: `${` no longer suppressed expansion of the rest of the string. Expanding the tail matches bash and the 2.x and 5.x lines, but it is a breaking change for 1.x, so return the remainder as a single literal as before - routed through `combine`, so `max` and `maxLength` still bound it. `test/dollar.js` only covered inputs where every group is `${`-prefixed and so could not detect this; widen it. Empty results were dropped against the whole string rather than against the current run. The old implementation recursed on `m.post`, so the drop tested only the expansion of the call's own substring, and the `{a},b}` rewrite starts a fresh such run part-way through a string by turning `isTop` back on. Collapsing that recursion into one accumulator lost the distinction, so `{a,b}{},}` gained two results. Track how much of each accumulator entry predates the current run and drop against that. Also fix the `maxLength` README example, which used a budget of 100 against ~1500-character expansions and so documented a result that is actually `[]`, and note that `expand` takes options in the API heading. --------- Co-authored-by: Julian Gruber <julian@juliangruber.com>
Configuration menu - View commit details
-
Copy full SHA for cb4b9e4 - Browse repository at this point
Copy the full SHA cb4b9e4View commit details -
Configuration menu - View commit details
-
Copy full SHA for d757f1d - Browse repository at this point
Copy the full SHA d757f1dView commit details -
Configuration menu - View commit details
-
Copy full SHA for 5c57cc2 - Browse repository at this point
Copy the full SHA 5c57cc2View commit details
Commits on Jul 30, 2026
-
* test: backport * fix: bound expansion length across comma alternatives and sequences * fix: don't count dropped empties against `max` Capping the intermediate `values` array at `max` entries counted alternatives that `combine` goes on to drop as empty, so `max` stopped bounding the number of *kept* results: `expand('{a,,b}', { max: 2 })` returned `['a']` where it used to return `['a', 'b']`. Skip those values rather than counting them. The cap itself stays - it is what bounds the array when the values are empty and so contribute no characters for `maxLength` to see. --------- Co-authored-by: Gareth Jones <3151613+G-Rath@users.noreply.github.com>Configuration menu - View commit details
-
Copy full SHA for 27fbeed - Browse repository at this point
Copy the full SHA 27fbeedView commit details -
Configuration menu - View commit details
-
Copy full SHA for 758fcd6 - Browse repository at this point
Copy the full SHA 758fcd6View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v1.1.12...v1.1.18