Skip to content

fix(deps): bump buger/jsonparser to v1.1.2 (GHSA-6g7g-w4f8-9c9x)#24

Merged
ClayMav merged 1 commit into
mainfrom
fix/jsonparser-cve
Apr 30, 2026
Merged

fix(deps): bump buger/jsonparser to v1.1.2 (GHSA-6g7g-w4f8-9c9x)#24
ClayMav merged 1 commit into
mainfrom
fix/jsonparser-cve

Conversation

@ClayMav
Copy link
Copy Markdown
Member

@ClayMav ClayMav commented Apr 29, 2026

Summary

Test plan

  • `go test ./...` passes locally
  • `go build ./...` clean
  • PR Validate workflow passes

GHSA-6g7g-w4f8-9c9x — denial of service in versions <= 1.1.1. Pulled in
indirectly via github.com/pb33f/libopenapi -> ordered-map -> jsonparser.
@ClayMav ClayMav requested a review from a team as a code owner April 29, 2026 23:23
@ClayMav ClayMav requested a review from haizhou-zhao April 29, 2026 23:23
@ClayMav ClayMav merged commit 75e8325 into main Apr 30, 2026
2 checks passed
@ClayMav ClayMav deleted the fix/jsonparser-cve branch April 30, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants