jsonpath icon indicating copy to clipboard operation
jsonpath copied to clipboard

fix vuls: CVE-2023-26115 relate to word-wrap dependency of static-eval, fix by pump static-eval to 2.1.1

Open andy3520 opened this issue 11 months ago • 0 comments

Hi, I use your library in my app, when I do code scanning with Snyk, it show that's a security issue in the dependencies

Its related to the word-wrap dependency of the static-eval (which is currently use by jsonpath) so I update the version of it.

Reference: CVE relate to word-wrap: https://nvd.nist.gov/vuln/detail/CVE-2023-26115 Snyk report: https://security.snyk.io/package/npm/static-eval

andy3520 avatar Feb 29 '24 09:02 andy3520