Skip to content

Vendor ply as it is no longer maintained, resolve CVE in the package by removing pickle functionality - #208

Merged
michaelmior merged 2 commits into
h2non:masterfrom
StateFarmIns:vendor-ply
Jan 27, 2026
Merged

Vendor ply as it is no longer maintained, resolve CVE in the package by removing pickle functionality#208
michaelmior merged 2 commits into
h2non:masterfrom
StateFarmIns:vendor-ply

Conversation

@jmahlik

@jmahlik jmahlik commented Jan 26, 2026

Copy link
Copy Markdown

Vendor ply as it is no longer maintained
related #206

@dtbayles

Copy link
Copy Markdown

i beg 🙏🏻🙏🏻🙏🏻🙏🏻

@mikedorfman

Copy link
Copy Markdown

Thank you for working on this!

@michaelmior
michaelmior merged commit eeed776 into h2non:master Jan 27, 2026
7 checks passed
@michaelmior

Copy link
Copy Markdown
Collaborator

Thanks @jmahlik!

@lantrix

lantrix commented Jan 28, 2026

Copy link
Copy Markdown

Will there be a new release with this fix?

@lfvdavid

lfvdavid commented Feb 2, 2026

Copy link
Copy Markdown

Can we have a new release with this fix?

lantrix added a commit to seek-oss/jsonpath-ng that referenced this pull request Feb 4, 2026
But it wasn't removed here, so it's being detected as a dependency by vulnerability scanning tools.
@lantrix lantrix mentioned this pull request Feb 4, 2026
@dtbayles

dtbayles commented Feb 5, 2026

Copy link
Copy Markdown

@jmahlik when can we expect a release on this?

@jmahlik

jmahlik commented Feb 5, 2026

Copy link
Copy Markdown
Author

I'm not a core maintainer on this project, just did the PR to vendor it. Keep in mind the maintainers are doing this on their free time. I would suggest upvoting #206 with a thumbs up and hopefully they'll release a new version soon. They are paying attention to the issue tracker.

It can be difficult to wait if a dependency scanner is causing all kinds of issues for you but this "vulnerability" is questionable at best and jsonpath-ng wasn't event using the functionality in question so at least you've got that to stand on.

Thus is the dysfunctional CVE system we're meant to deal with.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants