Skip to content

Commit e89d940

Browse files
fix(security): upgrade path-to-regexp 8.3.0 to 8.4.0 (ReDoS) (#602)
Fixes CVE where multiple sequential optional groups generate exponentially growing regexes causing denial of service. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 170aa03 commit e89d940

File tree

2 files changed

+12
-0
lines changed

2 files changed

+12
-0
lines changed

packages/agent-os/extensions/copilot/package-lock.json

Lines changed: 11 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

packages/agent-os/extensions/copilot/package.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,7 @@
4242
"axios": "^1.6.0",
4343
"dotenv": "^17.3.1",
4444
"express": "^5.2.1",
45+
"path-to-regexp": "8.4.0",
4546
"winston": "^3.11.0"
4647
},
4748
"devDependencies": {

0 commit comments

Comments
 (0)