[Lldb-commits] [lldb] [mlir] [MLIR][lldb-dap] Update brace-expansion dependencies in VSCode plugins, resolving security alerts (PR #198549)

Maksim Levental via lldb-commits lldb-commits at lists.llvm.org
Tue May 19 16:14:41 PDT 2026


https://github.com/makslevental approved this pull request.

I think this is basically fine - I don't love that there are so many changed lines so I can't really eye-ball audit but I guess there's no way around that (I guess should be doing more regularly scheduled `npm update`s). One question I have a relative outsider to the `npm` ecoystem - is there any fear currently that getting such brand-spanking-new versions of the `npm` packages opens us up to any of the recent supply-chain attacks ([Shai-Hulud](https://www.stepsecurity.io/blog/shai-hulud-here-we-go-again-mass-npm-supply-chain-attack-hits-the-antv-ecosystem))?

https://github.com/llvm/llvm-project/pull/198549


More information about the lldb-commits mailing list