Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Impossible to install because of violation detected #2304

Closed
localhero44 opened this issue Oct 3, 2024 · 2 comments
Closed

Impossible to install because of violation detected #2304

localhero44 opened this issue Oct 3, 2024 · 2 comments

Comments

@localhero44
Copy link

localhero44 commented Oct 3, 2024

Hi,
I would like to use the latest version, as I have used MSW in the past and it works great.
Unfortunately in my company I can't install it, because a violation (CVE) has been detected since two weeks on this dependency: path-to-regexp

Here is the CVE found by our IQ server : CVE-2024-45296

Could you upgrade this dependency? Currently it is 6.3.0

Regards
David

@kettanaito
Copy link
Member

kettanaito commented Oct 5, 2024

Hi.

This has been discussed and resolved. See #2270, #2277, and #2294. The fix is addressed on the path-to-regexp side, they've backported it to the version range compatible with the one required by MSW.

@davidperbal
Copy link

Sorry, I hadn't found any reference to the same problem before posting it, my fault.
So path-to-regexp 6.3.0 is patched, but that thus version that was identified as vulnerable at my company.
Then today I've found a way to ask for a new scan of the npm dependencies and this time I was able to install MSW in its latest version 😀

@github-actions github-actions bot locked and limited conversation to collaborators Oct 28, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants