Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency upgrade due to vulnerabilities #14

Open
halfzebra opened this issue Sep 16, 2024 · 0 comments
Open

Dependency upgrade due to vulnerabilities #14

halfzebra opened this issue Sep 16, 2024 · 0 comments

Comments

@halfzebra
Copy link

halfzebra commented Sep 16, 2024

Hello friends,

Thank you for maintaining aws-sig4! 🙌

I'm probably not the first one to notice, that there are a few security vulnerabilities in dependencies https://mvnrepository.com/artifact/org.sharetribe/aws-sig4/0.1.4 (not sure if all of them are listed, because I get a bit different list from nvd-scan locally).

The most obvious culprit is buddy/buddy-core "1.2.0", which has quite a few vulnerabilities even in the latest release.

I'd be happy to work on a PR for the upgrade, but it seems like it would entail a switch from jdk15 to jdk18, which might include breaking changes(as far as I understand).

There's probably a reason why that upgrade didn't happen. 🤔

Let me know what you think!

PS: feel free to close this if I misunderstood the vulnerabilities and they are actually tolerable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant