You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
@joan38 it's obvious it's a vulnerability tool mistake, so we won't issue another version of ALPN APIs just to workaround a bug in the vulnerability tool.
This is more for https://github.com/eclipse/jetty.alpn.api but I can't open an issue there.
The latest version of the API is
1.1.3.v20160715
:https://mvnrepository.com/artifact/org.eclipse.jetty.alpn/alpn-api/1.1.3.v20160715
But it's flagged as vulnerable by https://github.com/jeremylong/DependencyCheck
I understand this is a false positive since I guess it's checking if the version number is greater or so.
Is there any solution to avoid this flagging? Like releasing a newer version?
See: http4s/blaze#235
Thanks
The text was updated successfully, but these errors were encountered: