You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The good news is, we have investigated those vulnerabilities and determined that we are not impacted by them.
The tricky part is that we inherit those dependencies via retrofit (they are not direct dependencies), so we rely on their dependency versioning. It looks like they recently put out a release after four years without one, so we need to see if it's feasible to update.
I am using Java duo-universal-sdk v1.1.3 and getting vulnerabilities reported from dependencies.
Vulnerabilities I get reported in IntelliJ, and with syft/grype are:
com.fasterxml.jackson.core:jackson-core:2.3.2
com.fasterxml.jackson.core:jackson-databind:2.3.2
com.squareup.okhttp3:okhttp:3.14.19
com.squareup.okio:okio:1.17.2
Can you please investigate?
The text was updated successfully, but these errors were encountered: