Update npm package jsonpath to v1.2.0 [SECURITY]#8362
Update npm package jsonpath to v1.2.0 [SECURITY]#8362hash-worker[bot] wants to merge 1 commit intomainfrom
jsonpath to v1.2.0 [SECURITY]#8362Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
3 Skipped Deployments
|
PR SummaryLow Risk Overview Refreshes Written by Cursor Bugbot for commit 0992959. This will update automatically on new commits. Configure here. |
🤖 Augment PR SummarySummary: Updates the Changes:
Technical Notes: This is a dependency-only change; runtime behavior should remain the same aside from incorporating upstream security fixes. 🤖 Was this summary useful? React with 👍 or 👎 |
This PR contains the following updates:
1.1.1->1.2.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2025-61140
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
Release Notes
dchester/jsonpath (jsonpath)
v1.2.0Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.