You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It'd be nice to keep our dependencies up to date of course, but CVEs in our dependencies are not security concern: the input of scalac/scaladoc is your own code, not some untrusted user input, and you don't need any exploit to get arbitrary code execution, just call a macro, so patching CVEs won't make you less vulnerable to untrusted input.
Compiler version
The issue exists in both versions
3.1.1-RC2
and3.1.2-DEV
of the Scala 3 software distribution.Affected Java library
Both Java libraries
jackson-databind 2.2.x
andliqp 0.6.x
are affected by over 40 CVE andjackson-databind
2.2.3
exists in all Scala 3 distributions since version 3.0.0.liqp
0.6.7
exists in versions 3.0.x up to 3.1.1-RC2.liqp
0.6.8
exists in version 3.1.2-DEV.Final Notes
liqp
as described in issue 3859 and I did not find any trace of another try.CC @sjrd @SethTisue
The text was updated successfully, but these errors were encountered: