CacheControl/json-rules-engine

Please upgrade dependency jsonpath-plus to 10.1.0 due to critical vulnerability

Closed this issue · 3 comments

Apparently there is a critical vulnerability with jsonpath-plus < 10.0.7

image

https://www.npmjs.com/package/jsonpath-plus

@Ben-CA thanks for raising this.

@CacheControl I think this furthers my desire to get the path handling out of the core engine since this dependency is a pain.

Yes please and thanks for this awesome engine.

Thanks for the quick response and update!