You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently Git security bot raised an alert that path-to-regexp dependency with version ^1.7.0 is vulnerable in react-router-dom@5.3.4 (latest released react-router-dom) library.
Not really sure that react-router-dom with 5 version will be patched since team is completely focused on a new 6 version. Resolution with 8.0.0 in package.json does not help and breaks application on start with internal module error.
Would be perfect if this vulnerability will be fixed in terms of 1.x.x package version since there is no chance to migrate to latest react-router-dom release on current moment in project I am working on.
Appreciate your attention!
Thanks!
tomdev10, jackcurtis-te, Tomahaawk, micalevisk and stbenjamNodGod, anttu, fengmk2 and stbenjam