path-to-regexp npm audit high vulnerable
envgap__nestjs__nest-13955
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
78408352d51098ff60782accc5b19a12e9fa40ae- Manifest
packages/core/package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
nestjs/nest #13955 · read the original issue
### Is there an existing issue for this? - [X] I have searched the existing issues ### Current behavior In express, @nestjs/core, @nestjs/platform-express there is a package used "path-to-regexp" what causes a npm high security vulnerable. For Version 0.1.7 there is a path 0.1.10 but for 3.2.0 there is no patch currently available. This should be updated. ### Minimum reproduction code https://github.com/pillarjs/path-to-regexp/commit/29b96b4a1de52824e1ca0f49a701183cc4ed476f ### Steps to reproduce npm install npm audit ### Expected behavior no high security vulnerable ### Package - [ ] I don't know. Or some 3rd-party package - [ ] <code>@nestjs/common</code> - [X] <code>@nestjs/core</code> - [ ] <code>@nestjs/microservices</code> - [X] <code>@nestjs/platform-express</code> - [X] <code>@nestjs/platform-fastify</code> - [ ] <code>@nestjs/platform-socket.io</code> - [ ] <code>@nestjs/platform-ws</code> - [ ] <code>@nestjs/testing</code> - [ ] <code>@nestjs/websockets</code> - [ ] Other (see below) ### Other package _No response_ ### NestJS version 10.3.10 ### Packages versions latest ### Node.js version 20 ### In which operating systems have you tested? - [X] macOS - [X] Windows - [X] Linux ### Other _No response_
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]