-
Notifications
You must be signed in to change notification settings - Fork 47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2024-45296 #225
Comments
Any solutions? |
Latest release of path-to-regexp includes the Tests fail for me though... |
|
Great, thanks for putting in the work, @alexpech12 ! |
@fatso83 would it be possible to backport the fix into v5.x.x so that versions 11.x - 17.x of sinon received this fix without a need to update to 18.x? |
@skazantsev That would be possible, but it's not as easy as it sounds. Refer to this issue: googleapis/nodejs-bigquery-storage#475 Upgrading path-to-regexp to version 8 means requiring Node versions >= 16, which means we would break compatibility with our supported versions (at the point of release of those major versions). |
Looks like nise is pulling in a vulnerable version of path-to-regexp
GHSA-9wv6-86v2-598j
The text was updated successfully, but these errors were encountered: