You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The vulnerable library is ultimately included through opensensus, but that repository has been archived on Github, and the code is since unmaintained. The vulnerable version of grpc is defined here.
As the library is unmaintained, no new versions are pushed as part of #1290
The text was updated successfully, but these errors were encountered:
Right - but this ticket is not about the vulnerable library (grpc-context) but that this project depends on an obsolete library (opensensus](io.opencensus:opencensus*)
This library has an ultimate dependency on a version of
grpc-context
(1.27.2
), which is vulnerable to several CVEs.The exact dependency chain is as follows:
The vulnerable library is ultimately included through opensensus, but that repository has been archived on Github, and the code is since unmaintained. The vulnerable version of grpc is defined here.
As the library is unmaintained, no new versions are pushed as part of #1290
The text was updated successfully, but these errors were encountered: