Snyk Vulnerability in Pushy 0.15.4 ([email protected]) #1099
Unanswered
anshumanS17
asked this question in
Q&A
Replies: 2 comments 1 reply
-
Can you please provide a link to the specific vulnerability? To manage expectations, most of the time, these are false alarms. It's probably true that there's a vulnerability in |
Beta Was this translation helpful? Give feedback.
0 replies
-
This was the vulnerability reported |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi,
I’ve noticed a high-severity vulnerability reported by Snyk in Pushy 0.15.4. The issue is related to the
[email protected]
dependency (used incom.eatthepath:[email protected]
›io.netty:[email protected]
›io.netty:[email protected]
).As per the documentation, Pushy 0.15.4 is the latest version, and it depends on [email protected], which has the vulnerability.
I have a few questions:
Is there a new version of Pushy planned that fixes this vulnerability?
Or, can I exclude [email protected] and try using a newer version of netty-handler that doesn't have the vulnerability? Would this be compatible with Pushy 0.15.4?
I’d appreciate your help and suggestions. Looking forward to your reply. Thanks.
Beta Was this translation helpful? Give feedback.
All reactions