Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dep: upgrade jsonpath-plus to fix critical vulnerability #3369

Merged
merged 1 commit into from
Oct 17, 2024

Conversation

dirkluijk
Copy link
Contributor

@dirkluijk dirkluijk commented Oct 16, 2024

Description

See: https://nvd.nist.gov/vuln/detail/CVE-2024-21534

Fixes: #3368

Pre-merge checklist

This is for use by the Artillery team. Please leave this in if you're contributing to Artillery.

  • Does this require an update to the docs?
  • Does this require a changelog entry?

@CLAassistant
Copy link

CLAassistant commented Oct 16, 2024

CLA assistant check
All committers have signed the CLA.

@hassy
Copy link
Member

hassy commented Oct 16, 2024

thank you @dirkluijk!

@dirkluijk
Copy link
Contributor Author

Can someone from the collaborators merge this MR? 😉

@gelsogrove
Copy link

Please Merge it !

@hassy hassy merged commit c34f4e2 into artilleryio:main Oct 17, 2024
37 of 41 checks passed
@dirkluijk dirkluijk deleted the fix-vulnerability branch October 17, 2024 15:39
@Panzki
Copy link

Panzki commented Oct 18, 2024

Hi, thanks for merging the dependency update so quickly. Can you tell anything about when this change is expected to be released? 😃

@hassy
Copy link
Member

hassy commented Oct 23, 2024

this is out in v2.0.21 now

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2024-21534 vulnerability
5 participants