{"id":1908935,"name":"json-pointer","ecosystem":"npm","description":"Some utilities for JSON pointers described by RFC 6901","homepage":"https://github.com/manuelstofer/json-pointer","licenses":"MIT","normalized_licenses":["MIT"],"repository_url":"https://github.com/manuelstofer/json-pointer","keywords_array":[],"namespace":null,"versions_count":13,"first_release_published_at":"2013-04-07T14:38:12.779Z","latest_release_published_at":"2022-02-17T14:56:31.652Z","latest_release_number":"0.6.2","last_synced_at":"2026-04-18T19:12:13.639Z","created_at":"2022-04-09T18:12:24.670Z","updated_at":"2026-04-18T19:12:13.639Z","registry_url":"https://www.npmjs.com/package/json-pointer","install_command":"npm install json-pointer","documentation_url":null,"metadata":{"funding":null,"dist-tags":{"latest":"0.6.2"}},"repo_metadata":{"id":484205,"uuid":"9277180","full_name":"manuelstofer/json-pointer","owner":"manuelstofer","description":"Some utilities for the JSON pointers described by RFC 6901","archived":false,"fork":false,"pushed_at":"2023-12-20T22:03:47.000Z","size":171,"stargazers_count":175,"open_issues_count":14,"forks_count":42,"subscribers_count":4,"default_branch":"master","last_synced_at":"2024-05-01T22:17:01.172Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/manuelstofer.png","metadata":{"files":{"readme":"Readme.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2013-04-07T13:45:43.000Z","updated_at":"2024-06-18T12:26:22.543Z","dependencies_parsed_at":"2024-06-18T12:26:16.713Z","dependency_job_id":"64906933-fc12-4d2b-9a4e-f8ab0bbbe1b5","html_url":"https://github.com/manuelstofer/json-pointer","commit_stats":{"total_commits":75,"total_committers":15,"mean_commits":5.0,"dds":0.5466666666666666,"last_synced_commit":"931b0f9c7178ca09778087b4b0ac7e4f505620c2"},"previous_names":[],"tags_count":11,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/manuelstofer","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":217672064,"owners_count":16213566,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"manuelstofer","name":"Manuel Stofer","uuid":"227334","kind":"user","description":"","email":"","website":null,"location":"zurich","twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/227334?v=4","repositories_count":78,"last_synced_at":"2024-04-14T08:23:54.177Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/manuelstofer","funding_links":[],"total_stars":1160,"followers":53,"following":24,"created_at":"2022-11-02T16:21:54.108Z","updated_at":"2024-04-14T08:24:04.129Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/manuelstofer","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/manuelstofer/repositories"},"tags":[{"name":"0.6.0","sha":"daca211a0b25824c1fa10890f4ff0c14f491ba3f","kind":"tag","published_at":"2016-10-17T10:27:19.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.6.0","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.6.0/manifests"},{"name":"0.5.0","sha":"635503755529cd0ed0f4801a771ef02d274c7678","kind":"tag","published_at":"2016-03-18T12:35:49.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.5.0","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.5.0/manifests"},{"name":"0.4.0","sha":"5f680d07ca25a562cb3a706083d1f78f23c7c880","kind":"tag","published_at":"2016-02-22T23:50:46.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.4.0","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.4.0/manifests"},{"name":"0.3.1","sha":"fb24154a397fcb61e202502aa610f0e36e0f13ec","kind":"tag","published_at":"2016-02-17T00:07:49.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.3.1","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.3.1/manifests"},{"name":"0.2.2","sha":"67b58204557cc6ac48b27b72e24914f12362497a","kind":"commit","published_at":"2014-09-20T04:25:55.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.2.2","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.2/manifests"},{"name":"0.2.1","sha":"3f0807d0efcd9b24394fa227b9b201de3fbb883a","kind":"commit","published_at":"2014-07-30T03:59:14.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.2.1","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.1/manifests"},{"name":"0.2.0","sha":"24b32a4025ef38f71c47ffbfd7c89ea35514bb03","kind":"commit","published_at":"2014-07-30T03:48:04.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.2.0","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.2.0/manifests"},{"name":"0.1.0","sha":"9605ce4bc50ce9f90cffedf6938ce015a579e1c5","kind":"commit","published_at":"2013-11-09T06:35:38.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.1.0","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.1.0/manifests"},{"name":"0.0.4","sha":"49aecf145d05dd53855779b5e8ea991cd46b3517","kind":"commit","published_at":"2013-09-08T11:45:36.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.0.4","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.4/manifests"},{"name":"0.0.3","sha":"7fafd28a3e34046366f60ef844b92934dc426187","kind":"commit","published_at":"2013-04-07T18:35:43.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.0.3","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.3/manifests"},{"name":"0.0.2","sha":"34d8b0e27a4590081b87df5c552a0776d18c51a9","kind":"commit","published_at":"2013-04-07T14:37:42.000Z","download_url":"https://codeload.github.com/manuelstofer/json-pointer/tar.gz/0.0.2","html_url":"https://github.com/manuelstofer/json-pointer/releases/tag/0.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/tags/0.0.2/manifests"}]},"repo_metadata_updated_at":"2024-09-08T13:43:43.786Z","dependent_packages_count":384,"downloads":14022857,"downloads_period":"last-month","dependent_repos_count":10449,"rankings":{"downloads":0.15845360489656665,"dependent_repos_count":0.24635262497800423,"dependent_packages_count":0.1435749374871808,"stargazers_count":4.19852804361618,"forks_count":4.240544840937177,"docker_downloads_count":0.16117155355703827,"average":1.5247709342453577},"purl":"pkg:npm/json-pointer","advisories":[{"uuid":"GSA_kwCzR0hTQS02eHJmLXE5NzctNXZnY84AAwmb","url":"https://github.com/advisories/GHSA-6xrf-q977-5vgc","title":"json-pointer vulnerable to Prototype Pollution","description":"A vulnerability, which was classified as critical, has been found in json-pointer up to 0.6.1. Affected by this issue is the function set of the file index.js. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. Upgrading to version 0.6.2 is able to address this issue. The patch is identified as 859c9984b6c407fc2d5a0a7e47c7274daa681941. It is recommended to upgrade the affected component. VDB-216794 is the identifier assigned to this vulnerability.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2022-12-26T09:30:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":9.8,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-4742","https://github.com/manuelstofer/json-pointer/pull/36","https://github.com/manuelstofer/json-pointer/commit/859c9984b6c407fc2d5a0a7e47c7274daa681941","https://vuldb.com/?ctiid.216794","https://vuldb.com/?id.216794","https://github.com/advisories/GHSA-6xrf-q977-5vgc"],"source_kind":"github","identifiers":["GHSA-6xrf-q977-5vgc","CVE-2022-4742"],"repository_url":"https://github.com/manuelstofer/json-pointer","blast_radius":0.0,"created_at":"2022-12-30T18:03:21.911Z","updated_at":"2026-04-05T20:05:46.196Z","epss_percentage":0.00103,"epss_percentile":0.28476,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eHJmLXE5NzctNXZnY84AAwmb","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS02eHJmLXE5NzctNXZnY84AAwmb","packages":[{"ecosystem":"npm","package_name":"json-pointer","versions":[{"first_patched_version":"0.6.2","vulnerable_version_range":"\u003c 0.6.2"}],"purl":"pkg:npm/json-pointer"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS02eHJmLXE5NzctNXZnY84AAwmb/related_packages","related_advisories":[]},{"uuid":"GSA_kwCzR0hTQS12NXZnLWc3cnEtMzYzd80W4Q","url":"https://github.com/advisories/GHSA-v5vg-g7rq-363w","title":"Prototype Pollution in json-pointer","description":"This affects versions of package `json-pointer` up to and including `0.6.1`. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-11-08T17:40:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.6,"cvss_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","references":["https://nvd.nist.gov/vuln/detail/CVE-2021-23820","https://github.com/manuelstofer/json-pointer/blob/master/index.js%23L78","https://snyk.io/vuln/SNYK-JS-JSONPOINTER-1577287","https://github.com/manuelstofer/json-pointer/pull/36","https://github.com/manuelstofer/json-pointer/commit/931b0f9c7178ca09778087b4b0ac7e4f505620c2","https://github.com/advisories/GHSA-v5vg-g7rq-363w"],"source_kind":"github","identifiers":["GHSA-v5vg-g7rq-363w","CVE-2021-23820"],"repository_url":"https://github.com/manuelstofer/json-pointer","blast_radius":0.0,"created_at":"2022-12-21T16:12:10.556Z","updated_at":"2026-04-18T06:08:24.161Z","epss_percentage":0.00522,"epss_percentile":0.66794,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NXZnLWc3cnEtMzYzd80W4Q","html_url":"https://advisories.ecosyste.ms/advisories/GSA_kwCzR0hTQS12NXZnLWc3cnEtMzYzd80W4Q","packages":[{"ecosystem":"npm","package_name":"json-pointer","versions":[{"first_patched_version":"0.6.2","vulnerable_version_range":"\u003c= 0.6.1"}],"purl":"pkg:npm/json-pointer","statistics":{"dependent_packages_count":384,"dependent_repos_count":10449,"downloads":14176586,"downloads_period":"last-month"},"affected_versions":["0.0.2","0.0.3","0.0.4","0.1.0","0.2.1","0.2.2","0.3.0","0.3.1","0.4.0","0.5.0","0.6.0","0.6.1"],"unaffected_versions":["0.6.2"]}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12NXZnLWc3cnEtMzYzd80W4Q/related_packages","related_advisories":[]},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdtZzQtdzN3NS14NXBj","url":"https://github.com/advisories/GHSA-7mg4-w3w5-x5pc","title":"Prototype pollution in json-pointer","description":"This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-05-10T18:37:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.0,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H","references":["https://nvd.nist.gov/vuln/detail/CVE-2020-7709","https://github.com/manuelstofer/json-pointer/pull/34","https://snyk.io/vuln/SNYK-JS-JSONPOINTER-596925","https://www.npmjs.com/package/json-pointer","https://github.com/manuelstofer/json-pointer/pull/34/files","https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-598862","https://github.com/advisories/GHSA-7mg4-w3w5-x5pc"],"source_kind":"github","identifiers":["GHSA-7mg4-w3w5-x5pc","CVE-2020-7709"],"repository_url":"https://github.com/manuelstofer/json-pointer","blast_radius":0.0,"created_at":"2022-12-21T16:13:06.540Z","updated_at":"2026-04-18T06:09:38.795Z","epss_percentage":0.01029,"epss_percentile":0.77249,"api_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdtZzQtdzN3NS14NXBj","html_url":"https://advisories.ecosyste.ms/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdtZzQtdzN3NS14NXBj","packages":[{"ecosystem":"npm","package_name":"json-pointer","versions":[{"first_patched_version":"0.6.1","vulnerable_version_range":"\u003c 0.6.1"}],"purl":"pkg:npm/json-pointer"}],"related_packages_url":"https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTdtZzQtdzN3NS14NXBj/related_packages","related_advisories":[]}],"docker_usage_url":"https://docker.ecosyste.ms/usage/npm/json-pointer","docker_dependents_count":316,"docker_downloads_count":102142684,"usage_url":"https://repos.ecosyste.ms/usage/npm/json-pointer","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/npm/json-pointer/dependencies","status":null,"funding_links":[],"critical":null,"issue_metadata":{"last_synced_at":"2024-09-05T23:00:04.493Z","issues_count":14,"pull_requests_count":31,"avg_time_to_close_issue":3583845.6666666665,"avg_time_to_close_pull_request":4051030.3181818184,"issues_closed_count":9,"pull_requests_closed_count":22,"pull_request_authors_count":18,"issue_authors_count":11,"avg_comments_per_issue":2.142857142857143,"avg_comments_per_pull_request":2.129032258064516,"merged_pull_requests_count":17,"bot_issues_count":0,"bot_pull_requests_count":6,"past_year_issues_count":0,"past_year_pull_requests_count":1,"past_year_avg_time_to_close_issue":null,"past_year_avg_time_to_close_pull_request":null,"past_year_issues_closed_count":0,"past_year_pull_requests_closed_count":0,"past_year_pull_request_authors_count":1,"past_year_issue_authors_count":0,"past_year_avg_comments_per_issue":null,"past_year_avg_comments_per_pull_request":0.0,"past_year_bot_issues_count":0,"past_year_bot_pull_requests_count":0,"past_year_merged_pull_requests_count":0,"issues_url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/repositories/manuelstofer%2Fjson-pointer/issues","maintainers":[{"login":"epoberezkin","count":7,"url":"https://issues.ecosyste.ms/api/v1/hosts/GitHub/authors/epoberezkin"}],"active_maintainers":[]},"versions_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-pointer/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-pointer/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-pointer/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-pointer/related_packages","codemeta_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/packages/json-pointer/codemeta","maintainers":[{"uuid":"esp","login":"esp","name":null,"email":"e.poberezkin@me.com","url":null,"packages_count":70,"html_url":"https://www.npmjs.com/~esp","role":null,"created_at":"2022-11-12T22:50:28.670Z","updated_at":"2022-11-12T22:50:28.670Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/esp/packages"},{"uuid":"manuelstofer","login":"manuelstofer","name":null,"email":"manuel@smallpdf.com","url":null,"packages_count":8,"html_url":"https://www.npmjs.com/~manuelstofer","role":null,"created_at":"2022-11-12T22:50:28.651Z","updated_at":"2022-11-12T22:50:28.651Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/npmjs.org/maintainers/manuelstofer/packages"}]}