Skip to content

fix vuls: CVE-2023-26115 relate to word-wrap dependency of static-eval, fix by pump static-eval to 2.1.1 #188

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

andy3520
Copy link

@andy3520 andy3520 commented Feb 29, 2024

Hi, I use your library in my app,
when I do code scanning with Snyk, it show that's a security issue in the dependencies

Its related to the word-wrap dependency of the static-eval (which is currently use by jsonpath) so I update the version of it.

Reference:
CVE relate to word-wrap: https://nvd.nist.gov/vuln/detail/CVE-2023-26115
Snyk report: https://security.snyk.io/package/npm/static-eval

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant