Skip to content

Commit

Permalink
fix(deps): update dependency find-my-way to v8.2.2 [security] (#11585)
Browse files Browse the repository at this point in the history
This PR contains the following updates:

| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [find-my-way](https://redirect.github.com/delvedor/find-my-way) |
[`8.2.0` ->
`8.2.2`](https://renovatebot.com/diffs/npm/find-my-way/8.2.0/8.2.2) |
[![age](https://developer.mend.io/api/mc/badges/age/npm/find-my-way/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![adoption](https://developer.mend.io/api/mc/badges/adoption/npm/find-my-way/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![passing](https://developer.mend.io/api/mc/badges/compatibility/npm/find-my-way/8.2.0/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|
[![confidence](https://developer.mend.io/api/mc/badges/confidence/npm/find-my-way/8.2.0/8.2.2?slim=true)](https://docs.renovatebot.com/merge-confidence/)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

### GitHub Vulnerability Alerts

####
[CVE-2024-45813](https://redirect.github.com/delvedor/find-my-way/security/advisories/GHSA-rrr8-f88r-h8q6)

### Impact

A bad regular expression is generated any time you have two parameters
within a single segment, when adding a `-` at the end, like `/:a-:b-`.

### Patches

Update to find-my-way v8.2.2 or v9.0.1. or subsequent versions.

### Workarounds

No known workarounds.

### References

-
[CVE-2024-45296](https://redirect.github.com/advisories/GHSA-9wv6-86v2-598j)
- [Detailed blog post about `path-to-regexp`
vulnerability](https://blakeembrey.com/posts/2024-09-web-redos/)

---

### Release Notes

<details>
<summary>delvedor/find-my-way (find-my-way)</summary>

###
[`v8.2.2`](https://redirect.github.com/delvedor/find-my-way/releases/tag/v8.2.2)

[Compare
Source](https://redirect.github.com/delvedor/find-my-way/compare/186c7db33c6c6aaf4e8e68199722e217bdd69337...v8.2.2)

⚠️ Security Release ⚠️

Fixes:
GHSA-rrr8-f88r-h8q6
CVE-2024-45813

**Full Changelog**:
delvedor/find-my-way@v8.2.0...v8.2.2

###
[`v8.2.1`](https://redirect.github.com/delvedor/find-my-way/compare/v8.2.0...186c7db33c6c6aaf4e8e68199722e217bdd69337)

[Compare
Source](https://redirect.github.com/delvedor/find-my-way/compare/v8.2.0...186c7db33c6c6aaf4e8e68199722e217bdd69337)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/redwoodjs/redwood).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOC44MC4wIiwidXBkYXRlZEluVmVyIjoiMzguODAuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
  • Loading branch information
renovate[bot] committed Sep 18, 2024
1 parent 705ea5b commit 09c2f06
Show file tree
Hide file tree
Showing 2 changed files with 6 additions and 6 deletions.
2 changes: 1 addition & 1 deletion packages/vite/package.json
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@
"dotenv-defaults": "5.0.2",
"execa": "5.1.1",
"express": "4.21.0",
"find-my-way": "8.2.0",
"find-my-way": "8.2.2",
"fs-extra": "11.2.0",
"http-proxy-middleware": "3.0.2",
"isbot": "5.1.17",
Expand Down
10 changes: 5 additions & 5 deletions yarn.lock
Original file line number Diff line number Diff line change
Expand Up @@ -8782,7 +8782,7 @@ __metadata:
dotenv-defaults: "npm:5.0.2"
execa: "npm:5.1.1"
express: "npm:4.21.0"
find-my-way: "npm:8.2.0"
find-my-way: "npm:8.2.2"
fs-extra: "npm:11.2.0"
glob: "npm:11.0.0"
http-proxy-middleware: "npm:3.0.2"
Expand Down Expand Up @@ -17539,14 +17539,14 @@ __metadata:
languageName: node
linkType: hard

"find-my-way@npm:8.2.0, find-my-way@npm:^8.0.0":
version: 8.2.0
resolution: "find-my-way@npm:8.2.0"
"find-my-way@npm:8.2.2, find-my-way@npm:^8.0.0":
version: 8.2.2
resolution: "find-my-way@npm:8.2.2"
dependencies:
fast-deep-equal: "npm:^3.1.3"
fast-querystring: "npm:^1.0.0"
safe-regex2: "npm:^3.1.0"
checksum: 10c0/f0f0370215f7b693729483481cd8c642a2e42e7ec7296f099faf46c523a3cac2bcafc24229dc971f87def36c5fa1fdf7f08a7238144affd2ab3c57f75b9aaca6
checksum: 10c0/ce462b2033e08a82fa79b837e4ef9e637d5f3e6763564631ad835b4e50b22e2123c0bf27c4fe6b02bc4006cd7949c0351d2b6b6f32248e839b10bdcbd3a3269f
languageName: node
linkType: hard

Expand Down

0 comments on commit 09c2f06

Please sign in to comment.