Skip to content

chore: bump asl-validator to 3.11.0 #640

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Jan 24, 2025

Conversation

lukehedger
Copy link
Contributor

This bumps asl-validator to version 3.11.0. This should address the RCE vulnerability in JSONPath Plus. This has already been addressed in the asl-validator dependency, which depends on jsonpath-plus.

@lukehedger
Copy link
Contributor Author

@horike37 Are you able to help get this merged? Thanks!

@yo-ga
Copy link

yo-ga commented Jan 21, 2025

This would fix #639

@ynishimura
Copy link
Collaborator

Thank you!

@ynishimura ynishimura merged commit 7d82a84 into serverless-operations:master Jan 24, 2025
1 check passed
@lukehedger
Copy link
Contributor Author

Thanks for merging @ynishimura. Do you know when a new version of the package will be published that will contain this update?

@lym953
Copy link

lym953 commented Mar 4, 2025

I'm also waiting on the release. Our project serverless-plugin-datadog uses serverless-step-functions and is also affected by this vulnerability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants