-
Notifications
You must be signed in to change notification settings - Fork 410
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CVE-2022-41853, CVE-2016-1000027, GHSA-jgvc-jfgh-rjvv #1463
Comments
It seems This is just based on analysis of the pom.xml in the master branch using 3.4.1 deps: 3.4.0 deps: |
@sean-redmond Thanks for reporting. I'll quickly look into it. Will be fixed in #1464 |
I think the PR only resolves |
Maybe it's possible to exclude the affected packages, but I don't know if it's worth it. Do you have any hard limits? |
Here's what I did
Here's what I got
Here's what I was expecting
Here's what I think could be improved
Bump package versions to resolve, the spring framework one could be more difficult as it looks to be a major version
The text was updated successfully, but these errors were encountered: