-
Notifications
You must be signed in to change notification settings - Fork 466
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
vulnerable dependencies flagged by WhiteSource #416
Comments
sahilpalvia
pushed a commit
to sahilpalvia/amazon-kinesis-client
that referenced
this issue
Sep 24, 2018
sahilpalvia
pushed a commit
to sahilpalvia/amazon-kinesis-client
that referenced
this issue
Sep 24, 2018
sahilpalvia
added a commit
that referenced
this issue
Sep 25, 2018
sahilpalvia
added a commit
that referenced
this issue
Sep 25, 2018
Thanks for reporting this. We have upgraded the version of the guava library for KCL v1.x and v2.x. They should be available with 2.0.3 (released) and once 1.9.3 is available. As for the jackson dependencies, they come from the AWS SDK, and you can read here for the fix . |
sahilpalvia
added
v1.x
Issues related to the 1.x version
v2.x
Issues related to the 2.x version
labels
Oct 10, 2018
Thanks for the quick turnaround |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hi,
We are using the KCL jars and our IT Sec department has flagged the following dependency jars as vulnerable:
Could a new version be created with dependencies to patched versions?
Thanks
The text was updated successfully, but these errors were encountered: