Skip to content

Conversation

KirillLogin
Copy link

@KirillLogin KirillLogin commented Mar 19, 2019

According to NexusIQ and National Vulnerability Database dom4j.dom4j:1.6.1 contains CVE-2018-1000632 vulnerability.
It is nesessary to upgrade dom4j up to 2.1.1 version with groupId changing to resolve it.

@khmarbaise
Copy link
Member

Could you please squash your commits and make an update in the ReleaseNotes on your branch....so I appreciate to merge this...

@khmarbaise khmarbaise added Dependency Upgrade Upgraded dependency security Possible security findings labels Apr 15, 2019
@khmarbaise khmarbaise added this to the Release 0.4.0 milestone Apr 15, 2019
@khmarbaise
Copy link
Member

Unfortunately no feedback. Solve via #426

@khmarbaise khmarbaise closed this Sep 14, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependency Upgrade Upgraded dependency security Possible security findings
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants