@isaacs/brace-expansion

npm

Is @isaacs/brace-expansion safe to use?

Based on the latest brin safety scan, no vulnerabilities or threats were detected for @isaacs/brace-expansion v5.0.0. Trust score: 55/100. 1 known CVE, no detected threat patterns, and no suspicious capabilities identified. This is an automated, point-in-time assessment.

Install (safety-checked)

@isaacs/brace-expansion Passed Security Checks

No security concerns detected

clean
CVEs

1

Threats

0

Install Scripts

0

@isaacs/brace-expansion CVE Vulnerabilities (1)

@isaacs/brace-expansion has Uncontrolled Resource Consumption

Fixed in: 5.0.1

brin Recommendations

  • Update to a patched version to address 1 high-severity CVE.

Install with brin add @isaacs/brace-expansion to automatically apply these checks before installation.

This is an automated, point-in-time assessment and may contain errors. Findings are risk indicators, not confirmed threats. Security posture may change over time. Maintainers can dispute findings via the brin review process.

@isaacs/brace-expansion Capabilities & Permissions

No system capabilities detected for @isaacs/brace-expansion. It does not appear to access the network, filesystem, spawn processes, or use native modules. No capability concerns identified for use with AI coding agents.

AGENTS.md for @isaacs/brace-expansion

Good instructions lead to good results. brin adds @isaacs/brace-expansion documentation to your AGENTS.md so your agent knows how to use it properly—improving both safety and performance.

brin init

Vercel's research: 100% accuracy with AGENTS.md vs 53% without →

@isaacs/brace-expansion Documentation & Source Code

For the full @isaacs/brace-expansion README, API documentation, and source code, visit the official package registry.

Frequently asked questions about @isaacs/brace-expansion safety

Weekly Downloads

29.0M

Version

5.0.0

License

MIT

Other Versions

Last Scanned

Feb 1, 2026

Trust Score

55/100·Legitimacy signals, not safety

CVEs (1)

GHSA-7h2j-956f-4vf2

@isaacs/brace-expansion has Uncontrolled Resource Consumption

Fixed in: 5.0.1

Capabilities

No special capabilities detected

Is @isaacs/brace-expansion Safe? | npm Safety Scan - brin