Skip to content

Commit 5c60865

Browse files
pranavjain97claude
andcommitted
ci: add path-to-regexp override for CVE-2026-4867
Override path-to-regexp to ^0.1.13 to fix ReDoS vulnerability. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent 7b4e1d1 commit 5c60865

2 files changed

Lines changed: 5 additions & 3 deletions

File tree

package-lock.json

Lines changed: 4 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -141,6 +141,7 @@
141141
"serialize-javascript": "^7.0.3",
142142
"@isaacs/brace-expansion": "^5.0.1",
143143
"underscore": "^1.13.8",
144+
"path-to-regexp": "^0.1.13",
144145
"tough-cookie": "^4.1.3",
145146
"validator": "^13.15.22",
146147
"node-forge": "^1.3.2",

0 commit comments

Comments
 (0)