asyncapi / asyncapi/generator

[BUG] Snyk vulnerability in version asyncapi/generator 2.5.0

Open
#1,323 11 comments 0 reactions 0 assignees View on GitHub
bug
Dominant language
JavaScript
Stars
1.1k
Forks
397
Avg merge
1d 7h
Merged PRs (30d)
25

Description

### Describe the bug.

A critical vulnerability has been reported for the package jsonpath-plus, which originates from @asyncapi/generator@1.15.1.
To address this, we have upgraded @asyncapi/generator to versions 2.4.0 and even tested with the latest version 2.5.0. However, the issue persists along the following dependency path:

lib@* › @asyncapi/generator@2.4.0 › @asyncapi/parser@3.0.0-next-major-spec.8 › jsonpath-plus@7.2.0

To resolve this, jsonpath-plus needs to be upgraded to version 10.2.0, but unfortunately, we are not able to do it, so could you please help us to upgrade jsonpath-plus to 10.2.0 or can you guide how it can be done..

### Expected behavior

Snyk vulnerabilities should not appear on the snyk board under below mentioned path:
image

### How to Reproduce

1. As suggested in SNYK org, I have upgraded @asyncapi/generator to versions 2.4.0 but still snyk vuln was showing up
2. I then upgraded to 2.5.0 which is the latest version of @asyncapi/generator
3. but still Vul is showing up in SNYK org and it is suggesting upgrading jsonpath-plus to 10.2.0
4. so need help/suggestion on upgrading jsonpath-plus to 10.2.0

### 🥦 Browser

None

### 👀 Have you checked for similar open issues?

- [X] I checked and didn't find similar issue

### 🏢 Have you read the Contributing Guidelines?

- [X] I have read the [Contributing Guidelines](https://github.com/asyncapi/.github/blob/master/CONTRIBUTING.md)

### Are you willing to work on this issue ?

None

Contributor guide

Open the contributing guide

Research direction

Trace the reported dependency path through @asyncapi/generator 2.5.0 and @asyncapi/parser to reproduce the Snyk result. Done means jsonpath-plus resolves to 10.2.0 without breaking the generator and the vulnerability no longer appears in Snyk.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, nodejs
Domain
security, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.