You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@thrift.apache.org by "Jens Geyer (Jira)" <ji...@apache.org> on 2022/02/08 16:17:00 UTC

[jira] [Commented] (THRIFT-5512) CVEs notified on Maven Central (through deps)

    [ https://issues.apache.org/jira/browse/THRIFT-5512?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17488981#comment-17488981 ] 

Jens Geyer commented on THRIFT-5512:
------------------------------------

{quote}Consider fixing the dep versions and doing a minor release.{quote}
Consider sending a pull request.

> CVEs notified on Maven Central (through deps)
> ---------------------------------------------
>
>                 Key: THRIFT-5512
>                 URL: https://issues.apache.org/jira/browse/THRIFT-5512
>             Project: Thrift
>          Issue Type: Bug
>    Affects Versions: 0.15.0
>            Reporter: Divye Kapoor
>            Priority: Minor
>
> Consider fixing the dep versions and doing a minor release.
> Maven central identifies indirect CVEs:
> https://mvnrepository.com/artifact/org.apache.thrift/libthrift/0.15.0



--
This message was sent by Atlassian Jira
(v8.20.1#820001)