Skip to content

Commit

Permalink
Mention v2.2.4 fix in v4.0.1 changelog entry
Browse files Browse the repository at this point in the history
  • Loading branch information
rhansen committed May 5, 2022
1 parent 5447f9e commit 32c9098
Showing 1 changed file with 9 additions and 0 deletions.
9 changes: 9 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,14 @@
# Notable Changes

## v4.0.1

Security fix:

* `getSub()` now returns `null` when it encounters a non-"own" property
(including `__proto__`) or any non-object while walking the given property
path. This should make it easier to avoid accidental prototype pollution
vulnerabilities.

## v4.0.0

Compatibility changes:
Expand Down

0 comments on commit 32c9098

Please sign in to comment.