Skip to content

Conversation

BrunoQuaresma
Copy link
Collaborator

@BrunoQuaresma BrunoQuaresma commented Mar 27, 2025

Fixes a transitive High severity dependency in path-to-regexp.

We've tried to upgrade to 2.5.0 (currently, the latest version) but there are some known bugs related to polyfills as this one. As shared in the comments, the latest version without this issue is 2.4.3.

@BrunoQuaresma BrunoQuaresma self-assigned this Mar 27, 2025
Copy link

@cdr-bot cdr-bot bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is a hotfix and has been automatically approved.

  • ✅ Base is main or release branch
  • ✅ Has hotfix label
  • ✅ Head is from coder/coder
  • ✅ Less than 100 lines

Copy link
Member

@matifali matifali left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ship it

@BrunoQuaresma BrunoQuaresma merged commit 3e64dce into main Mar 27, 2025
30 checks passed
@BrunoQuaresma BrunoQuaresma deleted the bq/chore-upgrade-msw branch March 27, 2025 15:00
@github-actions github-actions bot locked and limited conversation to collaborators Mar 27, 2025
@aslilac
Copy link
Member

aslilac commented Mar 28, 2025

@BrunoQuaresma looking at the diff of the lock file, this didn't actually resolve the issue. the version of path-to-regexp didn't get bumped.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy