Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Resolve path-to-regexp to v1.9.0 to resolve GHSA-9wv6-86v2-598j #27113

Merged
merged 2 commits into from
Sep 12, 2024

Conversation

danjm
Copy link
Contributor

@danjm danjm commented Sep 12, 2024

Description

This permanently fixes GHSA-9wv6-86v2-598j by resolving that package to a recently released version that does not having breaking changes and where the security vulnerability is resolved.

Open in GitHub Codespaces

Related issues

Fixes:

Manual testing steps

  1. Go to this page...

Screenshots/Recordings

Before

After

Pre-merge author checklist

Pre-merge reviewer checklist

  • I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed).
  • I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots.

@danjm danjm requested a review from a team as a code owner September 12, 2024 19:14
Copy link
Contributor

CLA Signature Action: All authors have signed the CLA. You may need to manually re-run the blocking PR check if it doesn't pass in a few minutes.

Copy link

socket-security bot commented Sep 12, 2024

Removed dependencies detected. Learn more about Socket for GitHub ↗︎

🚮 Removed packages: npm/[email protected]

View full report↗︎

@danjm danjm changed the title Resolve path-to-regexp to v1.9.0 to resolve GHSA-9wv6-86v2-598j fix: Resolve path-to-regexp to v1.9.0 to resolve GHSA-9wv6-86v2-598j Sep 12, 2024
@dbrans
Copy link
Contributor

dbrans commented Sep 12, 2024

@metamaskbot update-policies

vthomas13
vthomas13 previously approved these changes Sep 12, 2024
@metamaskbot
Copy link
Collaborator

Policies updated

Copy link

Copy link

codecov bot commented Sep 12, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 70.04%. Comparing base (dfc12b6) to head (e452e41).

Additional details and impacted files
@@           Coverage Diff            @@
##           develop   #27113   +/-   ##
========================================
  Coverage    70.04%   70.04%           
========================================
  Files         1435     1435           
  Lines        49920    49920           
  Branches     13980    13980           
========================================
  Hits         34963    34963           
  Misses       14957    14957           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@metamaskbot
Copy link
Collaborator

Builds ready [e452e41]
Page Load Metrics (1835 ± 62 ms)
PlatformPageMetricMin (ms)Max (ms)Average (ms)StandardDeviation (ms)MarginOfError (ms)
ChromeHomefirstPaint18221771597581279
domContentLoaded16022078181312459
load16382186183512962
domInteractive157432136
Bundle size diffs
  • background: 0 Bytes (0.00%)
  • ui: 157 Bytes (0.00%)
  • common: 0 Bytes (0.00%)

@vthomas13 vthomas13 merged commit b01f0c9 into develop Sep 12, 2024
78 checks passed
@vthomas13 vthomas13 deleted the resolve-GHSA-9wv6-86v2-598j branch September 12, 2024 20:33
@github-actions github-actions bot locked and limited conversation to collaborators Sep 12, 2024
@metamaskbot metamaskbot added release-12.6.0 Issue or pull request that will be included in release 12.6.0 release-12.3.0 Issue or pull request that will be included in release 12.3.0 and removed release-12.6.0 Issue or pull request that will be included in release 12.6.0 labels Sep 12, 2024
@metamaskbot
Copy link
Collaborator

Missing release label release-12.3.0 on PR. Adding release label release-12.3.0 on PR and removing other release labels(release-12.6.0), as PR was cherry-picked in branch 12.3.0.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
release-12.3.0 Issue or pull request that will be included in release 12.3.0 team-extension-platform
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants