Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High Vulnerability Issue of Dependency classgraph 4.8.60 #1259

Closed
dsubelman opened this issue Jul 23, 2024 · 6 comments
Closed

High Vulnerability Issue of Dependency classgraph 4.8.60 #1259

dsubelman opened this issue Jul 23, 2024 · 6 comments

Comments

@dsubelman
Copy link

The dependency classgraph version 4.8.60 has been reported to have a high-severity vulnerability.

References:

It appears that release 4.8.112 addresses and fixes this issue.

@dsubelman
Copy link
Author

Hi, have you been able to see this?

@ccleva
Copy link
Contributor

ccleva commented Nov 26, 2024

Hi @dsubelman, I released a maintenance version with this fixed. Details are in this discussion #1261

@jtablesaw jtablesaw deleted a comment from frankwondon Jan 2, 2025
@jtablesaw jtablesaw deleted a comment from frankwondon Jan 2, 2025
@benmccann
Copy link
Collaborator

It looks like this was fixed awhile back and just never released. I'll cut a release of this project. No need to fork it

<version>4.8.168</version>

Closing in favor of #1251

@dsubelman
Copy link
Author

@benmccann thanks for the update. When are you planning to release the new version?

@benmccann
Copy link
Collaborator

Soon. Please follow #1251

Hopefully it will be today, but I need to check on some of the other PRs to try to get them in as well

@dsubelman
Copy link
Author

@benmccann thanks again for the rapid response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants