Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Outdated okhttp dependency has several security vulnerabilities #1981

Open
gtoison opened this issue Nov 7, 2023 · 0 comments
Open

Outdated okhttp dependency has several security vulnerabilities #1981

gtoison opened this issue Nov 7, 2023 · 0 comments
Labels
needs-review issue/PR needs review from maintainer

Comments

@gtoison
Copy link

gtoison commented Nov 7, 2023

The okhttp and logging-interceptor dependencies (along with their own transitive dependencies) have a bunch of vulnerabilities:
square/okhttp#6738
square/okio#1280
https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/

I'm not sure if these vulnerabilities are an actual issue for web3j but they have been addressed already so upgrading isn't a bad idea

@gtoison gtoison added the needs-review issue/PR needs review from maintainer label Nov 7, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs-review issue/PR needs review from maintainer
Projects
None yet
Development

No branches or pull requests

1 participant