Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explicitly add a versioned dependency for path-to-regexp #2954

Merged
merged 1 commit into from
Sep 16, 2024

Conversation

Sanjay-Ganeshan
Copy link
Contributor

We depend on path-to-regexp, through the webserver framework Express, which I think is coming from webpack or docusaurus.

Versions of path-to-regexp 0.2.0 < version < 1.9.0 have a security vulnerability.
By explicitly specifying the version of path-to-regexp, yarn chooses the right versions for everything else.

Motivation

Address a security vulnerability

Have you read the Contributing Guidelines on pull requests?

Yes

Test Plan

Download nvm / node as needed (tested on node JS 20, Mac OS)

nvm use 20
npm install -g yarn

Then, install the website:

cd website
yarn

Last but not least, start the website on a local server, and browse it:

yarn start

It should work normally.

Related Issues and PRs

None

…rough Express.

The version specified addresses security vulnerabilities.
@facebook-github-bot facebook-github-bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Sep 16, 2024
@jesszzzz jesszzzz merged commit ce692bd into main Sep 16, 2024
61 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants