Explicitly add a versioned dependency for path-to-regexp #2954
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
We depend on path-to-regexp, through the webserver framework Express, which I think is coming from webpack or docusaurus.
Versions of path-to-regexp 0.2.0 < version < 1.9.0 have a security vulnerability.
By explicitly specifying the version of path-to-regexp, yarn chooses the right versions for everything else.
Motivation
Address a security vulnerability
Have you read the Contributing Guidelines on pull requests?
Yes
Test Plan
Download nvm / node as needed (tested on node JS 20, Mac OS)
Then, install the website:
Last but not least, start the website on a local server, and browse it:
It should work normally.
Related Issues and PRs
None