Skip to content

Bump json-smart version to 2.5.2 #265

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 3 commits into from
Apr 11, 2025
Merged

Conversation

mstruk
Copy link
Contributor

@mstruk mstruk commented Apr 11, 2025

json-smart is being pulled in transitively by JsonPath project and flagged by CVE scanners for CVE-2024-57699 warning. Even though we don't think we are affected due to how we use JsonPath, the fact that scanners flag the dependency makes users nervous.

This is a temporary override, to be removed once a new version of JsonPath is released.
See: json-path/JsonPath#1030

mstruk added 3 commits April 11, 2025 12:40
Signed-off-by: Marko Strukelj <[email protected]>
Signed-off-by: Marko Strukelj <[email protected]>
Signed-off-by: Marko Strukelj <[email protected]>
@mstruk mstruk added this to the 0.16.1 milestone Apr 11, 2025
@ppatierno ppatierno requested a review from a team April 11, 2025 13:01
Copy link
Member

@ppatierno ppatierno left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mstruk mstruk merged commit 12c393c into strimzi:main Apr 11, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants