-
Notifications
You must be signed in to change notification settings - Fork 286
v9.2.0 Provides transitive vulnerable dependency maven:com.google.guava:guava:31.1-jre #899
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
I couldn't figure out how to label this issue, so I've labeled it for a human to triage. Hang tight. |
Does anyone know when it will be fixed? |
UPDATE: |
Overriding transitive deps might be dangerous, and should be avoided :-( |
Maybe other bosses can take a hint from their colleague. |
Thanks folks, this should be now fixed in the latest release (v9.30) |
Thanks for the update! But I believe that should read v9.3.0 |
CVE-2023-2976 7.1 Files or Directories Accessible to External Parties vulnerability with High severity foun
The text was updated successfully, but these errors were encountered: