-
Notifications
You must be signed in to change notification settings - Fork 920
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[CVE-2024-45296] Bump path-to-regexp to 1.9.0, 3.3.0, and 6.3.0 #8197
[CVE-2024-45296] Bump path-to-regexp to 1.9.0, 3.3.0, and 6.3.0 #8197
Conversation
Signed-off-by: Miki <[email protected]>
Signed-off-by: Miki <[email protected]>
Manually backported to 2.17 with #8198 Needs to be backported to 2.x from main. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #8197 +/- ##
==========================================
- Coverage 64.04% 64.04% -0.01%
==========================================
Files 3740 3740
Lines 88608 88608
Branches 13799 13799
==========================================
- Hits 56746 56745 -1
- Misses 31264 31265 +1
Partials 598 598
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
… 3.3.0, and 6.3.0 #8197 (#8198) Signed-off-by: Miki <[email protected]>
* Revert 8176 Signed-off-by: Miki <[email protected]> * [CVE-2024-45296] Bump `path-to-regexp` to 1.9.0, 3.3.0, and 6.3.0 Signed-off-by: Miki <[email protected]> * Changeset file for PR #8197 created/updated --------- Signed-off-by: Miki <[email protected]> Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com> (cherry picked from commit 3c4dc9d) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
… (#8206) * Revert 8176 * [CVE-2024-45296] Bump `path-to-regexp` to 1.9.0, 3.3.0, and 6.3.0 * Changeset file for PR #8197 created/updated --------- (cherry picked from commit 3c4dc9d) Signed-off-by: Miki <[email protected]> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: opensearch-changeset-bot[bot] <154024398+opensearch-changeset-bot[bot]@users.noreply.github.com>
Description
[CVE-2024-45296] Bump path-to-regexp to 1.9.0, 3.3.0, and 6.3.0
Changelog
path-to-regexp
to 1.9.0, 3.3.0, and 6.3.0Check List
yarn test:jest
yarn test:jest_integration