Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVEs caused by dependency check gradle plugin itself? #336

Closed
ghost opened this issue Apr 5, 2023 · 1 comment
Closed

CVEs caused by dependency check gradle plugin itself? #336

ghost opened this issue Apr 5, 2023 · 1 comment

Comments

@ghost
Copy link

ghost commented Apr 5, 2023

I am using the gradle plugin in version 8.2.1. The task dependencyCheckAnalyze gives me three CVEs, which all seem to be transitive dependencies of the plugin itself:

@jeremylong
Copy link
Collaborator

sorry for the delayed reply - yes, I know about the CVEs. Some of them have been fixed and I do not believe any of them actually affect the security of ODC. We are still working on the h2 issue - it will be a breaking change when 11.0 is released.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant