Skip to content

Dependency to com.squareup.wire:wire-runtime:2.2.0 with CVEs #1128

Open
@eaglerainbow

Description

@eaglerainbow

Dependency Security Scans of our project indicate that through org.cloudfoundry:cloudfoundry-client:5.6.0-RELEASE (most recent version as of writing) the dependency com.squareup.wire:wire-runtime:2.2.0 is declared.
This version is known to be subject to (at least) 3 CVEs (evidence):

The most current version of wire-runtime is 4.0.1, dating from December 2021, which apparently has these CVEs fixed.

Is it possible for the project to bump to a newer version to resolve the associated security risks?

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency filetriagedInitial triage of issue has been performed

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions