Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WRR-21447: Updated dependency to fix vulnerabilities #258

Open
wants to merge 2 commits into
base: develop
Choose a base branch
from

Conversation

ion-andrusciac-lgp
Copy link
Contributor

Checklist

Issue Resolved / Feature Added

There were high vulnerability

path-to-regexp <0.1.12
Severity: high
Unpatched path-to-regexp ReDoS in 0.1.x - GHSA-rhx6-c78j-4q9w
fix available via npm audit fix --force
Will install [email protected], which is a breaking change
node_modules/express/node_modules/path-to-regexp
node_modules/gatsby/node_modules/path-to-regexp
express 4.0.0-rc1 - 4.21.1 || 5.0.0-alpha.1 - 5.0.0-beta.3
Depends on vulnerable versions of path-to-regexp
node_modules/express
gatsby 3.4.0-alpha-parallel.36 - 3.14.2 || 4.0.0-alpha-9689ff.4 - 4.0.0-zz-next.9 || 5.13.0-alpha-alt-image-cdn.38 - 5.15.0-next.0
Depends on vulnerable versions of path-to-regexp
node_modules/gatsby

Resolution

Added "path-to-regexp": "^0.1.12" into overrides

Additional Considerations

Links

WRR-21447

Comments

Enact-DCO-1.0-Signed-off-by: Ion Andrusciac [email protected]

Copy link
Contributor

@daniel-stoian-lgp daniel-stoian-lgp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants