Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: update jsonpath-plus to 10.3.0 to fix security vulnerability #54733

Merged
merged 1 commit into from
Mar 1, 2025

Conversation

devin-ai-integration[bot]
Copy link
Contributor

This PR updates the version of jsonpath-plus in the Docusaurus directory to address a security vulnerability. The current version is 7.2.0, which is vulnerable, and needs to be updated to at least version 10.3.0.

The update includes:

  1. Updating json-schema-faker from 0.5.4 to 0.5.8
  2. Adding a resolution for jsonpath-plus to ensure version 10.3.0 is used

The changes have been tested by successfully building the documentation locally.

Link to Devin run: https://app.devin.ai/sessions/1858b31214ce41b1b8f34f9040380fd5

Copy link
Contributor Author

🤖 Devin AI Engineer

Original prompt from [email protected]:

Hey @Devin can you update the version of jsonpath-plus that we're using in Docusaurus in ./docusaurus directory of airbytehq/airbyte repo?

I see this dependabot security alert:

```Dependabot cannot update jsonpath-plus to a non-vulnerable version
The latest possible version of jsonpath-plus that can be installed is 7.2.0.

The earliest fixed version is 10.3.0.```
If jsonpath-plus is a transient dependency, perhaps we should update all patch versions of other packages to keep things up to date?

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add "(aside)" to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

Copy link

vercel bot commented Mar 1, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
airbyte-docs ✅ Ready (Inspect) Visit Preview 💬 Add feedback Mar 1, 2025 4:59am

@natikgadzhi natikgadzhi merged commit 401e34e into master Mar 1, 2025
24 checks passed
@natikgadzhi natikgadzhi deleted the devin/1740804436-update-jsonpath-plus branch March 1, 2025 05:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Development

Successfully merging this pull request may close these issues.

2 participants