You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A critical vulnerability has been reported for the package jsonpath-plus, which originates from @asyncapi/[email protected].
To address this, we have upgraded @asyncapi/generator to versions 2.4.0 and even tested with the latest version 2.5.0. However, the issue persists along the following dependency path:
To resolve this, jsonpath-plus needs to be upgraded to version 10.2.0, but unfortunately, we are not able to do it, so could you please help us to upgrade jsonpath-plus to 10.2.0 or can you guide how it can be done..
Expected behavior
Snyk vulnerabilities should not appear on the snyk board under below mentioned path:
How to Reproduce
As suggested in SNYK org, I have upgraded @asyncapi/generator to versions 2.4.0 but still snyk vuln was showing up
I then upgraded to 2.5.0 which is the latest version of @asyncapi/generator
but still Vul is showing up in SNYK org and it is suggesting upgrading jsonpath-plus to 10.2.0
so need help/suggestion on upgrading jsonpath-plus to 10.2.0
Welcome to AsyncAPI. Thanks a lot for reporting your first issue. Please check out our contributors guide and the instructions about a basic recommended setup useful for opening a pull request. Keep in mind there are also other channels you can use to interact with AsyncAPI community. For more details check out this issue.
Describe the bug.
A critical vulnerability has been reported for the package jsonpath-plus, which originates from @asyncapi/[email protected].
To address this, we have upgraded @asyncapi/generator to versions 2.4.0 and even tested with the latest version 2.5.0. However, the issue persists along the following dependency path:
lib@* › @asyncapi/[email protected] › @asyncapi/[email protected] › [email protected]
To resolve this, jsonpath-plus needs to be upgraded to version 10.2.0, but unfortunately, we are not able to do it, so could you please help us to upgrade jsonpath-plus to 10.2.0 or can you guide how it can be done..
Expected behavior
Snyk vulnerabilities should not appear on the snyk board under below mentioned path:
How to Reproduce
🥦 Browser
None
👀 Have you checked for similar open issues?
🏢 Have you read the Contributing Guidelines?
Are you willing to work on this issue ?
None
The text was updated successfully, but these errors were encountered: