Closed dependabot[bot] closed 2 weeks ago
Latest commit: 7d840de69c296a85fdeae8704f2bb31a5fe9f918
Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.
Click here to learn what changesets are, and how to add one.
Click here if you're a maintainer who wants to add a changeset to this PR
Issues
0 New issues
0 Accepted issues
Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code
/rtm
Bumps jsonpath-plus and @asyncapi/parser. These dependencies needed to be updated together. Updates
jsonpath-plus
from 7.1.0 to 10.1.0Release notes
Sourced from jsonpath-plus's releases.
Changelog
Sourced from jsonpath-plus's changelog.
... (truncated)
Commits
93612a3
chore: bump version4a16cbd
feat: add undefined, null literals to safe scriptf119fe3
feat: add typeof operator to safe scriptb70aa71
fix(security): preventconstructor
access in safe vm763ada0
fix(security): preventcall
/apply
invocation ofFunction
98a6b22
fix: remove overly aggressive disabling of native functions but disallow `__p...30194c7
fix(security): further prevent binding of Function calls which may evade dete...eac48fe
fix(security): prevent binding of Function calls which may evade detection34a836b
chore: bump version5a22e3f
fix(security): prevent Function calls outside of member expressionsUpdates
@asyncapi/parser
from 3.2.2 to 3.4.0Release notes
Sourced from
@asyncapi/parser
's releases.Commits
7c7c556
chore(release): version packages (#1059)e18f865
chore(deps): bump jsonpath-plus to ^10.0.0 to mitigate CVE-2024-21534 (#1058)dd8c9e8
docs: fix stringify example broken link in README (#1055)1560df3
chore(release): version packages (#1054)bebbd39
feat: create ruleasyncapi3-channel-no-query-nor-fragment
for v3 core rules...0d33904
chore(deps-dev): bump webpack from 5.93.0 to 5.94.0 (#1053)efc05af
fix: update@asyncapi/specs
to 6.8.0 version and others (#1052)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show