Skip to content

Conversation

Razican
Copy link
Member

@Razican Razican commented Oct 12, 2024

path-to-regexp has a critical vulnerability from 2.0.0 to 3.3.0, but @docusaurus/core depends on serve-handler, which has not been updated in years by @vercel.

I have added an override as recommended in vercel/serve-handler#212, and I'm following vercel/serve-handler#211 in case they update the dependency.

I also took the opportunity to update all other dependencies.

@Razican Razican added the dependencies Pull requests that update a dependency file label Oct 12, 2024
@Razican Razican requested a review from a team October 12, 2024 09:24
@jedel1043 jedel1043 merged commit 4427d39 into main Oct 12, 2024
1 check passed
@jedel1043 jedel1043 deleted the dep_update branch October 12, 2024 14:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants