Skip to content

build(deps): bump jsonpath-plus from 10.4.0 to 11.0.0 in /json - #483

Merged
thomasleplus merged 3 commits into
mainfrom
dependabot/npm_and_yarn/json/jsonpath-plus-11.0.0
Oct 2, 2026
Merged

thomasleplus merged 3 commits into
mainfrom
dependabot/npm_and_yarn/json/jsonpath-plus-11.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps jsonpath-plus from 10.4.0 to 11.0.0.

Release notes

Sourced from jsonpath-plus's releases.

v10.4.1

What's Changed

New Contributors

Full Changelog: JSONPath-Plus/JSONPath@v10.4.0...v10.4.1

Changelog

Sourced from jsonpath-plus's changelog.

11.0.0

BREAKING CHANGES

  • Require Node >= 22; drops older browser version support

  • JSONPath.cache is no longer exposed or mutable. Consumers that used JSONPath.cache to inspect, modify, or clear entries must remove that usage and call JSONPath.clearCache() when cache invalidation is needed.

  • chore: bump engines and browserslist and use v flag

  • chore: various changes in types, particularly with return values changing from any to unknown to ensure type safety (by forcing type casts of the results on the user).

  • fix!: isolate caches and add cache reset API

Other changes:

  • feat: add customTypes option for providing own other type callbacks (e.g., @blob()) (@​brettz9)
  • fix(slice): explicit zero end no longer returns the whole array (#265) (@​spokodev)
  • fix: indicate that the OtherTypeCallback callback type can accept a parentPropName with type number (@​brettz9)
  • fix: separate JSONPath path and script caches (@​brettz9)
  • fix: restore JSONPath.prototype.evaluate, safeVm, and vm compatibility
  • fix(safe-eval): harden operator lookup against prototype inheritance (@​brettz9)
  • fix(security): block indirect Function-constructor access in safe eval (reported by @c0rydoras: Arthur Deierlein <info@c0rydoras.dev>)
  • refactor: expose JSONPathClass prototype through JSONPath for compatibility
  • docs: security notes
  • test(safe-eval): guard bind() escape route for constructor access (@​brettz9)
  • test: restore full test coverage (@​brettz9)
  • chore: pnpm update (@​brettz9)
  • refactor: implement TypeScript-as-JSDoc and auto-build declaration files from this (avoiding need for maintaining declaration file manually)
  • chore: update devDeps
  • chore: lint
  • build(deps-dev): bump rollup from 4.53.2 to 4.59.0 (@​dependabot[bot])
  • build(deps): bump minimatch from 9.0.5 to 9.0.9 (@​dependabot[bot])
  • build(deps): bump serialize-javascript (via audit fix) (@​dependabot[bot])
  • build(deps): bump ajv from 6.12.6 to 6.14.0 (#253) (@​dependabot[bot])
  • build(deps): bump qs from 6.14.0 to 6.14.2 (#252) (@​dependabot[bot])
  • build(deps): bump markdown-it from 14.1.0 to 14.1.1 (#251) (@​dependabot[bot])
  • build(deps): bump minimatch from 3.1.2 to 3.1.4 (#255) (@​dependabot[bot])
Commits
  • a7afb58 chore: update types
  • bbb0141 chore: bump version (11.0.0)
  • 5313594 test(security): cover nested Function callback bypass
  • 3eace0d docs: CHANGES
  • 8ede5d9 chore: bump engines and browserslist and use v flag
  • fe892fc feat: add customTypes option for providing own other type callbacks (e.g., ...
  • cfc7ceb docs: credit Athrud Deierlein for security fix
  • d35778e chore: update build files
  • 4b2ebd7 build(deps): bump ip-address from 10.2.0 to 10.7.2
  • 7159cec build(deps): bump @​humanfs/node from 0.16.7 to 0.16.8
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [jsonpath-plus](https://github.com/s3u/JSONPath) from 10.4.0 to 11.0.0.
- [Release notes](https://github.com/s3u/JSONPath/releases)
- [Changelog](https://github.com/JSONPath-Plus/JSONPath/blob/main/CHANGES.md)
- [Commits](JSONPath-Plus/JSONPath@v10.4.0...v11.0.0)

---
updated-dependencies:
- dependency-name: jsonpath-plus
  dependency-version: 11.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Oct 2, 2026
@github-actions github-actions Bot added the build [Conventional Commits] Changes that affect the build system or external dependencies label Oct 2, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 2, 2026 12:14
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
npm/jsonpath-plus 11.0.0 🟢 4.6
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 1Found 3/27 approved changesets -- score normalized to 1
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Maintained🟢 1030 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Security-Policy🟢 10security policy file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • json/package-lock.json

@thomasleplus
thomasleplus merged commit 24ff718 into main Oct 2, 2026
54 checks passed
@thomasleplus
thomasleplus deleted the dependabot/npm_and_yarn/json/jsonpath-plus-11.0.0 branch October 2, 2026 20:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

build [Conventional Commits] Changes that affect the build system or external dependencies dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant