Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump path-to-regexp from 6.2.2 to 6.3.0 #11985

Closed
wants to merge 2 commits into from

Conversation

matiboux
Copy link
Contributor

@matiboux matiboux commented Sep 13, 2024

Changes

Bump path-to-regexp from 6.2.2 to 6.3.0.
Fixes CVE-2024-45296 (see GHSA-9wv6-86v2-598j).
Resolves #11956.

Related to #11956 (comment).

Testing

Just bumping to newly available patch to fix vulnerability.

Docs

N/A

Copy link

changeset-bot bot commented Sep 13, 2024

🦋 Changeset detected

Latest commit: 61f82c2

The changes in this PR will be included in the next version bump.

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@github-actions github-actions bot added the pkg: astro Related to the core `astro` package (scope) label Sep 13, 2024
@matiboux matiboux changed the title Bump path-to-regexp to 6.3.0 Bump path-to-regexp from 6.2.2 to 6.3.0 Sep 13, 2024
@delucis delucis closed this in 633eeaa Sep 13, 2024
@delucis
Copy link
Member

delucis commented Sep 13, 2024

Thanks for the PR @matiboux! We were actually able to remove dependency entirely in #11983 but appreciate you taking the time to help out 💜

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
pkg: astro Related to the core `astro` package (scope)
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Astro relies on vulnerable path-to-regexp
2 participants