[BUG] Snyk vulnerability in version asyncapi/generator 2.5.0
- Dominant language
- JavaScript
- Stars
- 1.1k
- Forks
- 397
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 25
Description
### Describe the bug.
A critical vulnerability has been reported for the package jsonpath-plus, which originates from @asyncapi/generator@1.15.1.
To address this, we have upgraded @asyncapi/generator to versions 2.4.0 and even tested with the latest version 2.5.0. However, the issue persists along the following dependency path:
lib@* › @asyncapi/generator@2.4.0 › @asyncapi/parser@3.0.0-next-major-spec.8 › jsonpath-plus@7.2.0
To resolve this, jsonpath-plus needs to be upgraded to version 10.2.0, but unfortunately, we are not able to do it, so could you please help us to upgrade jsonpath-plus to 10.2.0 or can you guide how it can be done..
### Expected behavior
Snyk vulnerabilities should not appear on the snyk board under below mentioned path:
### How to Reproduce
1. As suggested in SNYK org, I have upgraded @asyncapi/generator to versions 2.4.0 but still snyk vuln was showing up
2. I then upgraded to 2.5.0 which is the latest version of @asyncapi/generator
3. but still Vul is showing up in SNYK org and it is suggesting upgrading jsonpath-plus to 10.2.0
4. so need help/suggestion on upgrading jsonpath-plus to 10.2.0
### 🥦 Browser
None
### 👀 Have you checked for similar open issues?
- [X] I checked and didn't find similar issue
### 🏢 Have you read the Contributing Guidelines?
- [X] I have read the [Contributing Guidelines](https://github.com/asyncapi/.github/blob/master/CONTRIBUTING.md)
### Are you willing to work on this issue ?
None
Contributor guide
Research direction
Trace the reported dependency path through @asyncapi/generator 2.5.0 and @asyncapi/parser to reproduce the Snyk result. Done means jsonpath-plus resolves to 10.2.0 without breaking the generator and the vulnerability no longer appears in Snyk.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100