-
Notifications
You must be signed in to change notification settings - Fork 271
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
1544 update jsonpath package #1545
Conversation
resolves #1544 |
What is the timeframe for this PR to get reviewed, approved and merged? |
We are working on upgrading POC: 7ab2f4e#diff-9e03680efb5f8da7b469de8eb39f499e8e696a20f9085319dbb4d7a17e794717R14 |
Hey @milanmayr, will there be any breaking change if i override the "jsonpath-plus" to ^10.0.0 in order to mitigate the risk in my project until the fix is merged? |
Yes, I believe so, because in the newer version, the |
@jaredperreault-okta considering y'all are already working on this, should I abandon this PR and let all discussion continue in #1544 ? |
@chaitanyareddy-mula Yes. |
This PR is closed -- work on this can be followed at 7ab2f4e#diff-9e03680efb5f8da7b469de8eb39f499e8e696a20f9085319dbb4d7a17e794717R14 |
Addressed in 7.8.1 (released on npm) |
Update jsonpath package to remediate CVE-2024-21534