Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable package org.scala-lang:scala-library:2.13.3 included in sfp-lite packages for 38.4.1 and 39.0.3 #92

Closed
thraco opened this issue Jul 9, 2024 · 5 comments
Assignees

Comments

@thraco
Copy link

thraco commented Jul 9, 2024

Describe the bug
#49 did not completely resolve the issue raised in #46 by @JonnyPower. scala-library:2.13.3 is still included in the published packages for 38.4.1 and 39.0.3. #47 was closed without merging, but did include the upgrade of this package to 2.13.13.

To Reproduce
Steps to reproduce the behavior:

Expected behavior
sfp-lite no longer includes scala-library:2.13.3, which has the critical vulnerability CVE-2022-36944

azlam-abdulsalam pushed a commit that referenced this issue Jul 10, 2024
Update apexlink to 3.1.2 to fix issue #92
@azlam-abdulsalam
Copy link

@thraco thanks for brining this into attention, we will release a patch asap

@thraco
Copy link
Author

thraco commented Jul 10, 2024

thanks @azlam-abdulsalam!

dieffrei added a commit that referenced this issue Jul 12, 2024
Update apexlink to 3.1.2 to fix issue #92

Co-authored-by: azlam <[email protected]>
Co-authored-by: Diéffrei Quadros <[email protected]>
@azlam-abdulsalam
Copy link

We are facing some issues while rebuilding apexlink, will keep everyone posted when the patch is ready

@azlam-abdulsalam
Copy link

Fixed in 783b1c9

@thraco
Copy link
Author

thraco commented Jul 16, 2024

Fantastic, thank you @azlam-abdulsalam !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants