From ccd29f03ede2aecadac9c39fda95a5fedfb23645 Mon Sep 17 00:00:00 2001 From: danfickle Date: Mon, 22 Mar 2021 21:56:14 +1100 Subject: [PATCH] #8 1.0.8 security release --- CHANGELOG.md | 8 +++++++- README.md | 8 +++++++- 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 1de5fe489..eb09a0ad4 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,12 @@ ## CHANGELOG -### head - 1.0.8-SNAPSHOT +### head - 1.0.9-SNAPSHOT ++ See commit log. + + +### 1.0.8 (2021-March-22) +**SECURITY RELEASE** + + [#675](https://github.com/danfickle/openhtmltopdf/issues/675) Update PDFBOX to 2.0.23 to avoid CVEs. Thanks for reporting @Samuel3. NOTE: These CVEs relate to the loading of untrusted PDFs in PDFBOX and thus this project is not directly affected. However, it is not a good idea to have CVEs on your classpath. diff --git a/README.md b/README.md index 5f629e6f0..fec10f6b8 100644 --- a/README.md +++ b/README.md @@ -67,7 +67,13 @@ from ````/openhtmltopdf-examples/src/main/java/com/openhtmltopdf/testcases/Testc ## CHANGELOG -### head - 1.0.8-SNAPSHOT +### head - 1.0.9-SNAPSHOT ++ See commit log. + + +### 1.0.8 (2021-March-22) +**SECURITY RELEASE** + + [#675](https://github.com/danfickle/openhtmltopdf/issues/675) Update PDFBOX to 2.0.23 to avoid CVEs. Thanks for reporting @Samuel3. NOTE: These CVEs relate to the loading of untrusted PDFs in PDFBOX and thus this project is not directly affected. However, it is not a good idea to have CVEs on your classpath.