# Fix the Dependabot nth-check ReDoS Alert

> Understand why the nth-check ReDoS Dependabot alert is a false positive in Create React App builds, and when you actually need to upgrade nth-check

**URL:** https://sentry.io/answers/github-dependabot-alert-inefficient-regular-expression-complexity-in-nth-check/

---

## The Problem

> **Note:** [Create React App](https://create-react-app.dev/) was [deprecated by the React team in February 2025](https://react.dev/blog/2025/02/14/sunsetting-create-react-app). It still runs in maintenance mode, so the guidance below is accurate for existing Create React App projects, but new projects should use a framework like Next.js or a build tool like Vite instead.

When using Create React App to set up a single-page application in React, you may get a [GitHub Dependabot](https://docs.github.com/en/code-security/getting-started/dependabot-quickstart-guide#about-dependabot) security alert, similar to the following notification:

```
nth-check is vulnerable to Inefficient Regular Expression Complexity

Dependabot cannot update nth-check to a non-vulnerable version
The latest possible version that can be installed is 1.0.2 because of the following conflicting dependency:

react-scripts@4.0.3 requires nth-check@^1.0.2 via a transitive dependency on css-select@2.1.0
The earliest fixed version is 2.0.1.
```

## The Solution

If the problem is in a Create React App React application, you can ignore the warning.

The security alert occurs due to a [regular expression denial of service (ReDoS) vulnerability in `nth-check`](https://github.com/advisories/GHSA-rp65-9cf3-cjxr) that causes a denial of service when parsing specific invalid CSS nth-checks.

* The [`nth-check`](https://www.npmjs.com/package/nth-check) library is used to parse and compile `:nth-child()` and `:nth-last-of-type()` CSS [pseudo-classes](https://developer.mozilla.org/en-US/docs/Web/CSS/Pseudo-classes).

* Create React App is a build tool, and `nth-check` is a build-time dependency.

The ReDoS vulnerability isn't exploitable, as Create React App produces static HTML, CSS, and JavaScript.

Because the HTML, CSS, and JavaScript are static, the vulnerable code isn't part of the build. You can consider the security notification a false alarm.

Dependabot alerts and npm audits often give false positive security warnings for frontend tooling libraries, as explained in this [Create React App GitHub issue](https://github.com/facebook/create-react-app/issues/11174).

When using Create React App, you can set the GitHub Dependabot to ignore dependency warnings in the [configuration options of a `dependabot.yml` file](https://docs.github.com/en/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file#allow).

If, however, you're using `nth-check` as a dependency in an app where the vulnerable code could be exposed (such as in a Node.js app), you should update `nth-check` to version `2.0.1+` and update all packages that depend on the older version of `nth-check`.

---

*Source: [sentry.io/answers/github-dependabot-alert-inefficient-regular-expression-complexity-in-nth-check/](https://sentry.io/answers/github-dependabot-alert-inefficient-regular-expression-complexity-in-nth-check/)*
