Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue - commons-compress 1.18 #1347

Closed
saaryehudai opened this issue Jun 14, 2020 · 1 comment · Fixed by #1358
Closed

Security Issue - commons-compress 1.18 #1347

saaryehudai opened this issue Jun 14, 2020 · 1 comment · Fixed by #1358
Labels
bug project General project issues

Comments

@saaryehudai
Copy link

Information

snyk has marked commons-compress 1.18 as a high-security risk.
Details: https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-460507

We are using an old version of sbt-native-manager, but I see the current version still uses the marked version.

@muuki88 muuki88 added bug project General project issues labels Jun 17, 2020
@muuki88
Copy link
Contributor

muuki88 commented Jun 17, 2020

Thanks a lot for the issue report @saaryehudai

Would you like to open a pull request for this? I don't see this as an issue for native-packager as the developer building the package has any interest in ddosing his/her own machine or the CI, but keeping dependencies up-to-date is always a good thing.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug project General project issues
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants