From 3fbc59803b60dbed99fb11d8c9f9ce611f3efed8 Mon Sep 17 00:00:00 2001 From: Jeff Jacobson Date: Thu, 12 Sep 2024 09:12:49 -0700 Subject: [PATCH] build: :lock: Add override for path-to-regexp dependency See [msw seems to depend on vulnerable versions of path-to-regexp #2270](https://github.com/mswjs/msw/issues/2270) --- package-lock.json | 11 +++++++---- package.json | 5 +++++ 2 files changed, 12 insertions(+), 4 deletions(-) diff --git a/package-lock.json b/package-lock.json index 0938e370..eb145d64 100644 --- a/package-lock.json +++ b/package-lock.json @@ -11224,11 +11224,14 @@ "license": "ISC" }, "node_modules/path-to-regexp": { - "version": "6.2.2", - "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-6.2.2.tgz", - "integrity": "sha512-GQX3SSMokngb36+whdpRXE+3f9V8UzyAorlYvOGx87ufGHehNTn5lCxrKtLyZ4Yl/wEKnNnr98ZzOwwDZV5ogw==", + "version": "8.1.0", + "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-8.1.0.tgz", + "integrity": "sha512-Bqn3vc8CMHty6zuD+tG23s6v2kwxslHEhTj4eYaVKGIEB+YX/2wd0/rgXLFD9G9id9KCtbVy/3ZgmvZjpa0UdQ==", "dev": true, - "license": "MIT" + "license": "MIT", + "engines": { + "node": ">=16" + } }, "node_modules/path-type": { "version": "4.0.0", diff --git a/package.json b/package.json index d885a7b7..aaa5fc24 100644 --- a/package.json +++ b/package.json @@ -20,6 +20,11 @@ "test:watch": "vitest", "spell": "cspell ." }, + "overrides": { + "msw": { + "path-to-regexp": "^8.0.0" + } + }, "devDependencies": { "@arcgis/core": "^4.30.9", "@eslint/js": "^9.10.0",