Code Monkey home page Code Monkey logo

Comments (9)

sagold avatar sagold commented on June 19, 2024 1

Hi Ben.

Yes, I will take care if that. Thank you for the reminder.

from json-schema-library.

sagold avatar sagold commented on June 19, 2024 1

json-schema-library is published with an upgraded gson-pointer dependency: v7.3.7.

Your issue should be solved.

from json-schema-library.

benjdlambert avatar benjdlambert commented on June 19, 2024 1

Perfect! thanks for turning this around for us quickly! Have a great day! 🙏

from json-schema-library.

benjdlambert avatar benjdlambert commented on June 19, 2024

Nice thanks! Let me know if there's anything we can do to help! 🙏

from json-schema-library.

benjdlambert avatar benjdlambert commented on June 19, 2024

Thank you for the quick turnaround! 🙏

from json-schema-library.

benjdlambert avatar benjdlambert commented on June 19, 2024

@sagold it looks like the vulnerability is still there in the latest package however? Just tried with the latest 4.1.2 version and it's still possible to do prototype pollution with the latest version?

from json-schema-library.

sagold avatar sagold commented on June 19, 2024

yes I see the problem now. Will be done soon.

from json-schema-library.

benjdlambert avatar benjdlambert commented on June 19, 2024

OK perfect! Thank you again! 🙏

from json-schema-library.

sagold avatar sagold commented on June 19, 2024

Hi Ben.

  • the prototype pollution vulnerability has been fixed in gson-pointer
  • the vulerable devDependency watch has been removed from gson-pointer
  • gson-pointer was published with v4.1.3

In addition, a step which was overdue is to move gson-pointer package. This package will further be published under @sagold/json-pointer and is currently available with v5.0.0 (ahead of gson-pointer and includes the same patches).

Thus

  • with json-schema-library v7.3.8 the dependency was replaced by @sagold/[email protected]

running yarn audit results in 0 vulnerabilities.

If I missed something, send me response.

from json-schema-library.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.