← All tasks
javascriptnestjs/nest #13955Not a task: not reproduced

path-to-regexp npm audit high vulnerable

envgap__nestjs__nest-13955

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
78408352d51098ff60782accc5b19a12e9fa40ae
Manifest
packages/core/package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

nestjs/nest #13955 · read the original issue
### Is there an existing issue for this?



- [X] I have searched the existing issues



### Current behavior



In express, @nestjs/core, @nestjs/platform-express there is a package used "path-to-regexp" what causes a npm high security vulnerable. For Version 0.1.7 there is a path 0.1.10 but for 3.2.0 there is no patch currently available. 

This should be updated. 





### Minimum reproduction code



https://github.com/pillarjs/path-to-regexp/commit/29b96b4a1de52824e1ca0f49a701183cc4ed476f



### Steps to reproduce



npm install

npm audit



### Expected behavior



no high security vulnerable



### Package



- [ ] I don't know. Or some 3rd-party package

- [ ] <code>@nestjs/common</code>

- [X] <code>@nestjs/core</code>

- [ ] <code>@nestjs/microservices</code>

- [X] <code>@nestjs/platform-express</code>

- [X] <code>@nestjs/platform-fastify</code>

- [ ] <code>@nestjs/platform-socket.io</code>

- [ ] <code>@nestjs/platform-ws</code>

- [ ] <code>@nestjs/testing</code>

- [ ] <code>@nestjs/websockets</code>

- [ ] Other (see below)



### Other package



_No response_



### NestJS version



10.3.10



### Packages versions



latest



### Node.js version



20



### In which operating systems have you tested?



- [X] macOS

- [X] Windows

- [X] Linux



### Other



_No response_
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]