depath
v1.0.6npm· JavaScriptPath Matcher/Getter/Setter for Object/Array
The verdict
Has 1 high-severity advisory. Verify a patched version exists before using. Check the OSV link for the fixed-in version.
Check the OSV link for the fixed-in version.
Live from the npm registry · derived rules, not AI
How it scores
MaintenanceAbandoned
PopularityUnknown
Security1 advisory
LicensePermissive
DepsZero deps
Maintenance
Last published 5 years ago.
Popularity
Download count unavailable.
Security
1 known advisory (worst: high severity).
License
MIT
Dependencies
No runtime dependencies
Security advisories
Live from OSV.dev · cached 24h- HIGHdepath and cool-path vulnerable to Prototype Pollution via `set()` MethodGHSA-4h4x-4m75-47j4 Published 2025-03-28
Recent releases
- 1.0.65 years ago
- 1.0.55 years ago
- 1.0.45 years ago
- 1.0.35 years ago
- 1.0.25 years ago
- 1.0.15 years ago
- 1.0.05 years ago