Skip to content

Conversation

andy3520
Copy link

@andy3520 andy3520 commented Feb 29, 2024

Hi, I use your library in my app,
when I do code scanning with Snyk, it show that's a security issue in the dependencies

Its related to the word-wrap dependency of the static-eval (which is currently use by jsonpath) so I update the version of it.

Reference:
CVE relate to word-wrap: https://nvd.nist.gov/vuln/detail/CVE-2023-26115
Snyk report: https://security.snyk.io/package/npm/static-eval

@brunobastosg
Copy link

@dchester would you please merge this PR?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants