Skip to content

Conversation

@nordluf
Copy link

@nordluf nordluf commented Sep 12, 2024

path-to-regexp 0.2.0 - 1.8.0 || 4.0.0 - 7.2.0
Severity: high
path-to-regexp outputs backtracking regular expressions - GHSA-9wv6-86v2-598j

package.json Outdated
"path-to-regexp": "^6.2.1",
"path-to-regexp": "^8.1.0",
"qs": "^6.11.2",
"send": "^0.18.0",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Send also has a high severity warning. Can you also update it to 0.19.0?

Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@steven-sheehy send is not "high severity" warning, just "moderate". I updated the version, but that doesn't help as restify depends on the vulnerable version.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What are we waiting at the movement to get this PR merged?

@avoylenko
Copy link

Can this be merged?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants