-
Notifications
You must be signed in to change notification settings - Fork 10
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Dependency on the vulnerable org.json:json:20220320 #99
Comments
Hello Team, can you please provide your thoughts about the issue? Is it safe to run the client in production? Do you have plans to update the dependency? |
Also, I noticed that you already have a PR that addresses one of the vulnerabilities, but you didn't merge it, provide any response or fix the issue yourself. Why? |
@alok1111 thanks for creating this ticket. I am taking a look at this and will update soon. |
@izaaz is there any news? |
@alok1111 the patch was just released in version 1.12.1 |
Correction. The package has been deployed to a staging env. I'll update this issue once it's generally available. |
@izaaz thank you for the update. |
Thanks @alok1111. All packages are updated and use the version |
CVE-2023-5072
CVE-2022-45688
Expected Behavior
No dependencies with vulnerabilities
Current Behavior
2 High vulnerabilities
Possible Solution
Update
org.json:json
to the recent versionThe text was updated successfully, but these errors were encountered: