We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Hi,
It seems that nvd-clojure detects quite a few HIGH vulnerabilities due to the Batik dependencies version used in on-time:
nvd-clojure
on-time
batik-css-1.15.jar
CVE-2022-44729
CVE-2022-42890
CVE-2022-41704
CVE-2022-44730
batik-i18n-1.15.jar
It seems that this is for front-end purposes. Why are they actually needed? <- probably for QR rendering.
Is there any plan to upgrade these dependencies please?
The text was updated successfully, but these errors were encountered:
Actually, PR #24 from @daviddurand should solve these vulnerabilities.
Sorry, something went wrong.
No branches or pull requests
Hi,
It seems that
nvd-clojure
detects quite a few HIGH vulnerabilities due to the Batik dependencies version used inon-time
:batik-css-1.15.jar
:CVE-2022-44729
,CVE-2022-42890
,CVE-2022-41704
,CVE-2022-44730
batik-i18n-1.15.jar
:CVE-2022-44729
,CVE-2022-44730
It seems that this is for front-end purposes. Why are they actually needed?<- probably for QR rendering.Is there any plan to upgrade these dependencies please?
The text was updated successfully, but these errors were encountered: