Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: juliangruber/brace-expansion
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v1.1.12
Choose a base ref
...
head repository: juliangruber/brace-expansion
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v1.1.18
Choose a head ref
  • 15 commits
  • 12 files changed
  • 8 contributors

Commits on Mar 27, 2026

  1. Configuration menu
    Copy the full SHA
    7fd684f View commit details
    Browse the repository at this point in the history
  2. 1.1.13

    juliangruber committed Mar 27, 2026
    Configuration menu
    Copy the full SHA
    6c353ca View commit details
    Browse the repository at this point in the history

Commits on Apr 4, 2026

  1. Backport fix for GHSA-7h2j-956f-4vf2 to v1 (#101)

    Co-authored-by: Victorino Machava <victorino.machava@vm.co.mz>
    vitolob and Victorino Machava authored Apr 4, 2026
    Configuration menu
    Copy the full SHA
    0d7652e View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    2fbb6a2 View commit details
    Browse the repository at this point in the history

Commits on Apr 11, 2026

  1. Add opt-in { max } mitigation to v1 legacy line (#103)

    * Backport fix for GHSA-7h2j-956f-4vf2 to v1
    
    * Remove `EXPANSION_MAX` and default to unbounded expansion
    
    ---------
    
    Co-authored-by: Victorino Machava <victorino.machava@vm.co.mz>
    vitolob and Victorino Machava authored Apr 11, 2026
    Configuration menu
    Copy the full SHA
    1afa1b2 View commit details
    Browse the repository at this point in the history
  2. 1.1.14

    juliangruber committed Apr 11, 2026
    Configuration menu
    Copy the full SHA
    10c05fc View commit details
    Browse the repository at this point in the history

Commits on May 26, 2026

  1. Backport v5.0.6 change to v1 (#111)

    Co-authored-by: Siddharth Srinivasan <175113207+sid-srini@users.noreply.github.com>
    sid-srini and sid-srini authored May 26, 2026
    Configuration menu
    Copy the full SHA
    0b09384 View commit details
    Browse the repository at this point in the history
  2. 1.1.15

    juliangruber committed May 26, 2026
    Configuration menu
    Copy the full SHA
    2203f4f View commit details
    Browse the repository at this point in the history

Commits on Jul 8, 2026

  1. fix: v1 backport for CVE-2026-13149 (#122)

    * fix: backport for CVE-2026-13149
    
    * fix: backport for CVE-2026-13149
    
    * Consistency with v5 patch
    
    * Consistency with v5 patch
    
    * Consistency with v5 patch
    
    * Update test/unbound-recursion.js
    
    * Update test/unbound-recursion.js
    
    ---------
    
    Co-authored-by: Julian Gruber <julian@juliangruber.com>
    adam-tylr and juliangruber authored Jul 8, 2026
    Configuration menu
    Copy the full SHA
    d74e630 View commit details
    Browse the repository at this point in the history
  2. 1.1.16

    juliangruber committed Jul 8, 2026
    Configuration menu
    Copy the full SHA
    447763a View commit details
    Browse the repository at this point in the history

Commits on Jul 29, 2026

  1. fix: backport GHSA-mh99-v99m-4gvg (#129)

    * fix: default to a `max` of `100000`
    
    * fix: backport GHSA-mh99-v99m-4gvg
    
    * test: adopt the bounded default max on v1
    
    The backport changes the default `max` from `Infinity` to `EXPANSION_MAX`
    (100,000), matching v5. `test/sequence.js` still asserted the old
    unbounded behaviour, so the suite was red. Update both assertions to the
    capped default and add a single-sequence case exercising the cap.
    
    Otherwise keep 1.x's observable behaviour untouched, so this ships the
    vulnerability fixes and nothing else. Two places had drifted:
    
    `${` no longer suppressed expansion of the rest of the string. Expanding
    the tail matches bash and the 2.x and 5.x lines, but it is a breaking
    change for 1.x, so return the remainder as a single literal as before -
    routed through `combine`, so `max` and `maxLength` still bound it.
    `test/dollar.js` only covered inputs where every group is `${`-prefixed
    and so could not detect this; widen it.
    
    Empty results were dropped against the whole string rather than against
    the current run. The old implementation recursed on `m.post`, so the drop
    tested only the expansion of the call's own substring, and the `{a},b}`
    rewrite starts a fresh such run part-way through a string by turning
    `isTop` back on. Collapsing that recursion into one accumulator lost the
    distinction, so `{a,b}{},}` gained two results. Track how much of each
    accumulator entry predates the current run and drop against that.
    
    Also fix the `maxLength` README example, which used a budget of 100
    against ~1500-character expansions and so documented a result that is
    actually `[]`, and note that `expand` takes options in the API heading.
    
    ---------
    
    Co-authored-by: Julian Gruber <julian@juliangruber.com>
    G-Rath and juliangruber authored Jul 29, 2026
    Configuration menu
    Copy the full SHA
    cb4b9e4 View commit details
    Browse the repository at this point in the history
  2. npm ignore .claude

    juliangruber committed Jul 29, 2026
    Configuration menu
    Copy the full SHA
    d757f1d View commit details
    Browse the repository at this point in the history
  3. 1.1.17

    juliangruber committed Jul 29, 2026
    Configuration menu
    Copy the full SHA
    5c57cc2 View commit details
    Browse the repository at this point in the history

Commits on Jul 30, 2026

  1. Merge commit from fork

    * test: backport
    
    * fix: bound expansion length across comma alternatives and sequences
    
    * fix: don't count dropped empties against `max`
    
    Capping the intermediate `values` array at `max` entries counted
    alternatives that `combine` goes on to drop as empty, so `max` stopped
    bounding the number of *kept* results: `expand('{a,,b}', { max: 2 })`
    returned `['a']` where it used to return `['a', 'b']`.
    
    Skip those values rather than counting them. The cap itself stays - it is
    what bounds the array when the values are empty and so contribute no
    characters for `maxLength` to see.
    
    ---------
    
    Co-authored-by: Gareth Jones <3151613+G-Rath@users.noreply.github.com>
    juliangruber and G-Rath authored Jul 30, 2026
    Configuration menu
    Copy the full SHA
    27fbeed View commit details
    Browse the repository at this point in the history
  2. 1.1.18

    juliangruber committed Jul 30, 2026
    Configuration menu
    Copy the full SHA
    758fcd6 View commit details
    Browse the repository at this point in the history
Loading