Skip to content

Apply backtracking protection to version 1.8.0 due to "react-router-dom@5.3.4" #318

@dotnet-fizzyy

Description

@dotnet-fizzyy

Hi all!

Currently Git security bot raised an alert that path-to-regexp dependency with version ^1.7.0 is vulnerable in react-router-dom@5.3.4 (latest released react-router-dom) library.

Not really sure that react-router-dom with 5 version will be patched since team is completely focused on a new 6 version. Resolution with 8.0.0 in package.json does not help and breaks application on start with internal module error.

Would be perfect if this vulnerability will be fixed in terms of 1.x.x package version since there is no chance to migrate to latest react-router-dom release on current moment in project I am working on.

Appreciate your attention!
Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions