Skip to content

path-to-regexp vulnerability fix#1630

Merged
tomrf1 merged 1 commit intomainfrom
tf-path-to-regexp
Apr 13, 2026
Merged

path-to-regexp vulnerability fix#1630
tomrf1 merged 1 commit intomainfrom
tf-path-to-regexp

Conversation

@tomrf1
Copy link
Copy Markdown
Member

@tomrf1 tomrf1 commented Apr 13, 2026

express currently uses v0.1.13 of path-to-regexp, which has a vulnerability -
https://github.com/guardian/support-dotcom-components/security/dependabot/289
For now we must override it

@tomrf1 tomrf1 requested a review from a team as a code owner April 13, 2026 12:31
@tomrf1 tomrf1 added the dependencies Pull requests that update a dependency file label Apr 13, 2026
@tomrf1 tomrf1 merged commit 81947c6 into main Apr 13, 2026
6 of 7 checks passed
@tomrf1 tomrf1 deleted the tf-path-to-regexp branch April 13, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants