Security vulnerability affects the argo-workflows package. The NPM package braces, versions prior to 3.
braces
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LF83973.json"