Skip to content

Commit dbea8be

Browse files
antonisclaude
andcommitted
chore(deps): bump path-to-regexp to 0.1.12
Adds a parent-scoped yarn resolution to force express@4.19.2's path-to-regexp dependency from 0.1.7 to 0.1.12, patching ReDoS vulnerability (affected range: < 0.1.12). The 7.x consumers are unaffected. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 5a14e8e commit dbea8be

2 files changed

Lines changed: 5 additions & 4 deletions

File tree

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,7 @@
6060
],
6161
"resolutions": {
6262
"appium-chromedriver@npm:5.6.73/@xmldom/xmldom": "0.8.10",
63+
"express@npm:4.19.2/path-to-regexp": "0.1.12",
6364
"fast-xml-parser": "^5.3.6",
6465
"form-data": "4.0.4",
6566
"qs": "^6.14.2",

yarn.lock

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -28302,10 +28302,10 @@ __metadata:
2830228302
languageName: node
2830328303
linkType: hard
2830428304

28305-
"path-to-regexp@npm:0.1.7":
28306-
version: 0.1.7
28307-
resolution: "path-to-regexp@npm:0.1.7"
28308-
checksum: 69a14ea24db543e8b0f4353305c5eac6907917031340e5a8b37df688e52accd09e3cebfe1660b70d76b6bd89152f52183f28c74813dbf454ba1a01c82a38abce
28305+
"path-to-regexp@npm:0.1.12":
28306+
version: 0.1.12
28307+
resolution: "path-to-regexp@npm:0.1.12"
28308+
checksum: ab237858bee7b25ecd885189f175ab5b5161e7b712b360d44f5c4516b8d271da3e4bf7bf0a7b9153ecb04c7d90ce8ff5158614e1208819cf62bac2b08452722e
2830928309
languageName: node
2831028310
linkType: hard
2831128311

0 commit comments

Comments
 (0)