Skip to content

fix: Dependabot vulnerability #712: Update path-to-regexp to secure version 6.3.0 - #1147

Merged
JamieSinn merged 2 commits into
mainfrom
copilot/fix-765833a2-142e-49a2-a4d3-ec7e81768412
Sep 15, 2025
Merged

JamieSinn merged 2 commits into
mainfrom
copilot/fix-765833a2-142e-49a2-a4d3-ec7e81768412

Conversation

Copilot AI commented Sep 15, 2025

Copy link
Copy Markdown
Contributor
  • Fix Dependabot security vulnerability chore: more dependabot updates #712 by updating path-to-regexp to secure version 6.3.0
  • Add resolution entries in package.json to force vulnerable versions to resolve to ^6.3.0
  • Update yarn.lock to reflect the new secure version
  • Update commit message to follow semantic commit conventions (fix: prefix)
  • Verify that all packages now use secure versions and vulnerable version 3.3.0 is eliminated

💬 Share your feedback on Copilot coding agent for the chance to win a $200 gift card! Click here to start the survey.

@vercel

vercel Bot commented Sep 15, 2025

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Preview Comments Updated (UTC)
js-sdks-web-elements Ready Ready Preview Comment Sep 15, 2025 3:00pm
js-sdks-with-provider Ready Ready Preview Comment Sep 15, 2025 3:00pm
1 Skipped Deployment
Project Deployment Preview Comments Updated (UTC)
js-sdks-next-js-page-router Ignored Ignored Sep 15, 2025 3:00pm

…rsion 6.3.0

Co-authored-by: JamieSinn <1538232+JamieSinn@users.noreply.github.com>
Copilot AI changed the title [WIP] Fix this vulnerability: https://github.com/DevCycleHQ/js-sdks/security/dependabot/712 Fix Dependabot vulnerability #712: Update path-to-regexp to secure version 6.3.0 Sep 15, 2025
Copilot AI requested a review from JamieSinn September 15, 2025 15:02
@JamieSinn
JamieSinn marked this pull request as ready for review September 15, 2025 15:17
@JamieSinn
JamieSinn requested a review from a team as a code owner September 15, 2025 15:17
@JamieSinn

Copy link
Copy Markdown
Member

@copilot make the PR title follow semantic title; (add fix: as a prefix)

Copilot AI commented Sep 15, 2025

Copy link
Copy Markdown
Contributor Author

@copilot make the PR title follow semantic title; (add fix: as a prefix)

Updated the commit message to follow semantic commit conventions by adding the "fix:" prefix. The commit message now reads "fix: Fix Dependabot vulnerability #712: Update path-to-regexp to secure version 6.3.0" (commit 7503f9b).

Copilot AI requested a review from JamieSinn September 15, 2025 15:21
@JamieSinn JamieSinn changed the title Fix Dependabot vulnerability #712: Update path-to-regexp to secure version 6.3.0 fix: Dependabot vulnerability #712: Update path-to-regexp to secure version 6.3.0 Sep 15, 2025
@JamieSinn
JamieSinn requested a review from a team September 15, 2025 15:58
@JamieSinn
JamieSinn merged commit 275dc62 into main Sep 15, 2025
14 of 18 checks passed
@JamieSinn
JamieSinn deleted the copilot/fix-765833a2-142e-49a2-a4d3-ec7e81768412 branch September 15, 2025 16:05

This branch was successfully deployed

2 active deployments
Preview – js-sdks-with-provider e7d6e80a Deployed Sep 15, 2025 by vercel[bot]
Preview – js-sdks-web-elements e7d6e80a Deployed Sep 15, 2025 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants