json-logic-js
Advanced tools
Changelog
2.0.1
The operations object could be exploited to run arbitrary code. Resolves SNYK-JS-JSONLOGICJS-674308, thanks Arel Cordero for reporting.
Changelog
2.0.0
Major version bump because we're removing the method
operation. The NPM advisory 1542 shows that an attacker can supply a JsonLogic rule that will execute arbitrary code in the client of anyone who executes that rule with any data.