Skip to content

Query and manipulate JavaScript objects with JSONPath expressions. Robust JSONPath engine for Node.js.

JavaScript · active 2023-08-162026-05-20 (UTC)

Complete coverage26,342 / 26,342 hourly files (100%) · 2 absent upstream2023-08-152026-08-16 (UTC)
Events
282
Pushes
2
Pull requests
7
Issues
9
Stars
209
Forks
20

Activity over time

Daily event counts in the loaded window

Line chart, 1009 days from 2023-08-16 to 2026-05-20. Pushes: 2 total, peak 1 in a day. Pull requests: 7 total, peak 2 in a day. Issues: 9 total, peak 1 in a day. Comments: 35 total, peak 4 in a day. Stars: 209 total, peak 3 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

Recent activity

Latest issues, pull requests and releases

  • Issue comment#197molyholy2026-03-04 15:38
    Attempt to fix CVE-2026-1615 vulnerability
  • Issue#199Fnu-DevX2026-02-25 20:31
    Security: CVE-2026-1615 – Arbitrary Code Execution via unsanitized JSONPath expressions (static-eval)
  • Issue#196klyinliu2026-02-24 10:21
    SNYK report critical security vulnerability against all version of jsonpath
  • Pull request#197dfop022026-02-19 15:42
  • Issue comment#196chellman2026-02-18 22:01
    SNYK report critical security vulnerability against all version of jsonpath
  • Issue comment#196adelimon2026-02-17 14:35
    SNYK report critical security vulnerability against all version of jsonpath
  • Issue comment#196afiller2026-02-09 12:18
    SNYK report critical security vulnerability against all version of jsonpath
  • Issue comment#192CuriousPolymath2026-02-09 09:05
    Bump grunt from 0.4.5 to 1.5.3
  • Issue comment#194dchester2026-02-05 00:41
    CVE-2025-61140
  • Pull request#195dchester2026-02-04 23:56
  • Issue comment#194yasin2dev2026-02-03 14:16
    CVE-2025-61140
  • Issue comment#194ssudame22026-02-03 12:31
    CVE-2025-61140
  • Issue comment#194Dremig2026-02-03 08:21
    CVE-2025-61140
  • Pull request#195ssudame22026-02-01 12:49
  • Pull request#192dependabot[bot]2025-11-17 14:08
  • Pull request#192dependabot[bot]2025-11-17 14:08
  • Issue comment#66jjoselv2025-08-27 13:35
    use of instanceof is incorrect
  • Issue comment#188brunobastosg2025-07-22 16:41
    fix vuls: CVE-2023-26115 relate to word-wrap dependency of static-eval, fix by pump static-eval to 2.1.1
  • Issue comment#89thetumper2025-05-21 13:15
    Webpack cannot find module "fs"
  • Issue comment#159jsutter9092025-04-30 23:28
    Updating the version of static-eval used in jsonpath
  • Issue#191zhbtman1232025-03-27 06:46
    number start on key name
  • Issue comment#168mgoulet1012024-10-16 18:21
    cannot bundle with CDK/esbuild and use in AWS Lambda
  • Issue#190clifrocks3112024-10-11 17:48
    querying throws an error if the key in the object starts with a number.
  • Issue comment#117elisherer2024-09-19 16:17
    AssertionError [ERR_ASSERTION]: obj needs to be an object
  • Issue comment#86roshie5482024-08-09 05:21
    Extracting subset of fields from JSON object

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 209 stars here means stars gained during the window, not the repo's star count.