-
Notifications
You must be signed in to change notification settings - Fork 72
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade packages that have security vulnerabilities. #288
Comments
Hey Christopher! We just released the 1.1.4 version where the dependency versions have been upgraded. Both of the High ones got fixed in that. |
jackson-chris
added a commit
to jackson-chris/stocator
that referenced
this issue
Jul 2, 2021
@mrmadira any reason the associated PR for this has yet to be merged? |
Can you pls share the relevant findings for twistlock? And what version of tt are you using? Are the findings against 1.1.4 version of the jar? IBM-SDK version / with dependencies etc..? |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Several dependencies used by this project have logged security vulnerabilities:
Should try and attempt to use the fixed versions of these jars even if the vulnerable code paths are not used in the product to assure consumers the product is vulnerability free.
The text was updated successfully, but these errors were encountered: