Skip to content

Conversation

@FerencKemeny
Copy link

Fixing the transition vulnerability reported by dependabot. CVE-2024-26308 and CVE-2024-25710 are coming from org.apache.commons:commons-compress:1.24.0 (and CVE-2024-47554 is originated from commons-io:commons-io:2.13.0). It seems like these vulnerabilities are fixed from org.apache.commons:commons-compress:1.26.0. However the latest available version is 1.27.1.

@FerencKemeny FerencKemeny requested a review from a team March 9, 2025 17:40
@FerencKemeny FerencKemeny closed this by deleting the head repository Mar 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant