I recently checked my dependabot page and I found this error here:
Dependabot cannot update nth-check to a non-vulnerable version
The latest possible version that can be installed is 1.0.2 because of the following
conflicting dependency:
react-scripts@5.0.1 requires nth-check@^1.0.2 via a transitive dependency on css-
select@2.1.0
The earliest fixed version is 2.0.1.
and I was wondering if that might be a false alarm because I read on another Stack Overflow post that the same error is most likely to be a false alarm
https://stackoverflow.com/questions/71282206/github-dependabot-alert-inefficient-regular-expression-complexity-in-nth-check#:~:text=As%20Dan%20Abramov%20explains%20in%20this%20issue%2C%20it%20is%20(very%20likely)%20a%20false%20alarm%20and%20can%20be%20safely%20dismissed
Also to add, I have ran npm audit and it gave me these:
nth-check <2.0.1
Severity: high
Inefficient Regular Expression Complexity in nth-check -
https://github.com/advisories/GHSA
fix available via `npm audit fix --force`
Will install react-scripts@2.1.3, which is a breaking change
node_modules/svgo/node_modules/nth-check
css-select <=3.1.0
Depends on vulnerable versions of nth-check
node_modules/svgo/node_modules/css-select
svgo 1.0.0 - 1.3.2
Depends on vulnerable versions of css-select
node_modules/svgo
@svgr/plugin-svgo <=5.5.0
Depends on vulnerable versions of svgo
node_modules/@svgr/plugin-svgo
@svgr/webpack 4.0.0 - 5.5.0
Depends on vulnerable versions of @svgr/plugin-svgo
node_modules/@svgr/webpack
react-scripts >=2.1.4
Depends on vulnerable versions of @svgr/webpack
node_modules/react-scripts
6 high severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
My project uses Auth0 with thier authentication system. Please tell me if I need to include any more details!
Thanks,
324hz win21H2 he/him