Skip to content

Conversation

@draial
Copy link
Contributor

@draial draial commented Dec 2, 2024

This PR aims to fix a transitive DoS vulnerability detected via the dependency okhttp:4.10.0 > okio:3.0.0. Version 3.4.0 contained a fix.

Sources:

The closest non-transitively-vulnerable okhttp version is 4.12.

@draial
Copy link
Contributor Author

draial commented Dec 2, 2024

this is related to #205, but also updates the corresponding test library version

@beavuck
Copy link

beavuck commented Dec 3, 2024

@sdiakovskyi-gd @szagr

Pinging the latest two contributors I could find :) do you think this could make it into a version 5.2.6?

@mdmytrash
Copy link
Collaborator

Hello, @draial
Thank you for your contribution

@mdmytrash mdmytrash merged commit db0ab24 into mailjet:master Jan 13, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants