-
-
Notifications
You must be signed in to change notification settings - Fork 240
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Release a new package to include the patch for CVE-2024-21534 critical vulnerability #2717
Comments
We're working on a pipeline problem to fix this and get it released. The ETA is early next week. |
I highly appreciate your prompt response and dedication on the open-source work. Thank you! |
Hi @mnaumanali94, manage to get the pipeline problem fixed? Would really appreciate a new release of this :) |
@mnaumanali94 Is there anything the rest of the community can do to help support getting the pipeline issue resolved? I too am sitting tight awaiting the new release and would be willing to help troubleshoot whatever is going on! |
Can we reopen this issue? |
@jacquesg Apologies for the delay here. We should have it out tomorrow. The team got pulled into some other things. 🙏🏼 I'll post the details here as we get it out. |
Thank you @mnaumanali94, appreciate the effort. |
Thank you so much! |
@mnaumanali94 Hi, sorry for bringing this issue back from the dead, but jsonpath-plus@10.1.0 unfortunately doesn’t fix the vulnerability. The latest version, 10.2.0, does remediation the security issue. See:
Would you please update the version or use a caret ^ for jsonpath-plus for https://github.com/stoplightio/spectral/blob/develop/packages/core/package.json#L50 or would you accept a PR? Thank you for your time on this too. |
Thanks for reporting @davidensinger - we'll take a look. |
Chore summary
Release a new package to include the patch for CVE-2024-21534 critical vulnerability covered in #2709
Tasks
Additional context
N/A
The text was updated successfully, but these errors were encountered: