Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update path-to-regexp to 3.3.0 #1257

Merged
merged 1 commit into from
Sep 16, 2024

Conversation

MikeMcC399
Copy link
Collaborator

Issue

The following example directories report high severity vulnerabilities due to their transient dependency usage of path-to-regexp@2.2.1:

Check with npm audit:

Check with pnpm audit:

yarn audit shows no issue, however Dependabot reports the vulnerability:

Change

Pin to path-to-regexp@3.3.0 using the appropriate option according to the package manager being used:

@MikeMcC399 MikeMcC399 added bug Something isn't working type: dependencies labels Sep 14, 2024
@MikeMcC399 MikeMcC399 self-assigned this Sep 14, 2024
@cypress-app-bot
Copy link

@MikeMcC399 MikeMcC399 marked this pull request as ready for review September 14, 2024 13:11
@jennifer-shehane jennifer-shehane merged commit f8960d5 into cypress-io:master Sep 16, 2024
74 checks passed
@MikeMcC399 MikeMcC399 deleted the fix/path-to-regexp branch September 16, 2024 11:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working type: dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

path-to-regexp@2.2.1 vulnerability
3 participants