You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In currently latest version of twitter::chill, kryo-shaded 4.0.2 is used, which has security vulnerability BDSA-2016-1151: Allows DoS via Java Serialization API. And this security risk is fixed in kryo 5.3.0.
Is this possible to upgrade using the higher version kryo?
The text was updated successfully, but these errors were encountered:
PRs are accepted and if the CI can be made green we merge. Unfortunately, this basically a community effort at this time, and my role (note: I left Twitter 7 years ago) is to contribute some time reviewing.
In currently latest version of twitter::chill, kryo-shaded 4.0.2 is used, which has security vulnerability BDSA-2016-1151: Allows DoS via Java Serialization API. And this security risk is fixed in kryo 5.3.0.
Is this possible to upgrade using the higher version kryo?
The text was updated successfully, but these errors were encountered: