Skip to content

patch: Patch high severity path-to-regexp vulnerability#215

Closed
alana-cruickshank wants to merge 1 commit intovercel:mainfrom
alana-cruickshank:fix/ISSUE-212
Closed

patch: Patch high severity path-to-regexp vulnerability#215
alana-cruickshank wants to merge 1 commit intovercel:mainfrom
alana-cruickshank:fix/ISSUE-212

Conversation

@alana-cruickshank
Copy link
Copy Markdown

@alana-cruickshank alana-cruickshank commented Oct 12, 2024

closes #211
closes #212
see GHSA-9wv6-86v2-598j

@socket-security
Copy link
Copy Markdown

New and removed dependencies detected. Learn more about Socket for GitHub ↗︎

Package New capabilities Transitives Size Publisher
npm/@istanbuljs/load-nyc-config@1.1.0 environment, filesystem +1 18.3 kB coreyfarrell
npm/aggregate-error@3.1.0 None 0 6.69 kB sindresorhus
npm/append-transform@2.0.0 None 0 8.33 kB jakxz
npm/caching-transform@4.0.0 filesystem 0 10.1 kB coreyfarrell
npm/cliui@6.0.0 None +1 20.6 kB bcoe
npm/default-require-extensions@3.0.1 filesystem +1 7.25 kB sindresorhus
npm/find-cache-dir@3.3.2 filesystem 0 6.79 kB sindresorhus
npm/foreground-child@3.3.0 shell Transitive: environment, filesystem +3 170 kB isaacs
npm/fromentries@1.3.2 None 0 4.95 kB feross
npm/get-package-type@0.1.0 filesystem 0 6.01 kB coreyfarrell
npm/is-windows@1.0.2 None 0 7.96 kB jonschlinkert
npm/istanbul-lib-hook@3.0.0 unsafe 0 17.9 kB coreyfarrell
npm/istanbul-lib-instrument@6.0.3 Transitive: environment +19 8.83 MB oss-bot
npm/istanbul-lib-processinfo@2.0.3 environment, filesystem 0 16.1 kB isaacs
npm/node-preload@0.2.1 environment 0 9.22 kB coreyfarrell
npm/nyc@17.1.0 environment, filesystem, unsafe +2 83.2 kB bcoe
npm/path-to-regexp@3.3.0 None 0 25.8 kB blakeembrey
npm/process-on-spawn@1.0.0 shell 0 7.47 kB coreyfarrell
npm/spawn-wrap@2.0.0 environment, filesystem, shell, unsafe +1 43.5 kB coreyfarrell
npm/test-exclude@6.0.0 None 0 23.6 kB coreyfarrell
npm/uuid@8.3.2 None 0 116 kB ctavan
npm/wrap-ansi@6.2.0 None +1 36.7 kB sindresorhus
npm/yargs@15.4.1 environment, filesystem +1 302 kB oss-bot

🚮 Removed packages: npm/append-transform@1.0.0, npm/caching-transform@3.0.2, npm/cliui@5.0.0, npm/cp-file@6.2.0, npm/default-require-extensions@2.0.0, npm/find-cache-dir@2.1.0, npm/foreground-child@1.5.6, npm/istanbul-lib-coverage@2.0.5, npm/istanbul-lib-hook@2.0.7, npm/istanbul-lib-instrument@3.3.0, npm/istanbul-lib-report@2.0.8, npm/istanbul-lib-source-maps@3.0.6, npm/istanbul-reports@2.2.7, npm/merge-source-map@1.1.0, npm/nested-error-stacks@2.1.0, npm/nyc@14.1.1, npm/os-homedir@1.0.2, npm/path-to-regexp@2.2.1, npm/spawn-wrap@1.4.3, npm/test-exclude@5.2.3, npm/wrap-ansi@5.1.0, npm/yargs@13.3.2

View full report↗︎

@alana-cruickshank alana-cruickshank changed the title patch: Patch path-to-regexp vulnerability patch: Patch high severity path-to-regexp vulnerability Oct 13, 2024
@AndyBitz
Copy link
Copy Markdown
Contributor

Thank you for your PR!

Since there were some other changes that caused this PR to have merge conflicts I've created #217 to get those changes into the next release.

@AndyBitz AndyBitz closed this Oct 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

High severity vulnerabilities / serve-handler / path-to-regexp path-to-regexp-2.2.1.tgz High severity dependency path-to-regexp

2 participants