-
-
Notifications
You must be signed in to change notification settings - Fork 446
Closed
Description
Hi all!
Currently Git security bot raised an alert that path-to-regexp
dependency with version ^1.7.0 is vulnerable in [email protected]
(latest released react-router-dom
) library.
Not really sure that react-router-dom
with 5 version will be patched since team is completely focused on a new 6 version. Resolution with 8.0.0
in package.json
does not help and breaks application on start with internal module error.
Would be perfect if this vulnerability will be fixed in terms of 1.x.x
package version since there is no chance to migrate to latest react-router-dom
release on current moment in project I am working on.
Appreciate your attention!
Thanks!
tomdev10, jackcurtis-te, Tomahaawk, micalevisk and stbenjamNodGod, anttu, fengmk2 and stbenjam
Metadata
Metadata
Assignees
Labels
No labels