Skip to content

Conversation

@seabass-labrax
Copy link
Contributor

This is to safeguard users of java-spdx-library against a vulnerability (CVE-2021-44228) which could potentially allow remote code execution.

Signed-off-by: Sebastian Crane [email protected]

@goneall
Copy link
Member

goneall commented Dec 11, 2021

Thanks @seabass-labrax - I'm surprised the dependabot didn't catch this one.

As soon as it passes the CI checks, I'll merge this in for the next release.

@seabass-labrax
Copy link
Contributor Author

Hmm, the CI failure is strange... 'worked on my machine', as they say! :D

@goneall
Copy link
Member

goneall commented Dec 11, 2021

@seabass-labrax I'm working on a PR #72 to fix - once I get it working for the me, I'll ask you to rebase and try again. Having some challenges with the github action syntax :( Stay tuned ...

@goneall
Copy link
Member

goneall commented Dec 13, 2021

@seabass-labrax I just merged in what I think will fix the CI. If you could rebase to the current master branch and see if this will now pass.

This is to safeguard users of java-spdx-library against a vulnerability
(CVE-2021-44228) which could potentially allow remote code execution.

Signed-off-by: Sebastian Crane <[email protected]>
@seabass-labrax
Copy link
Contributor Author

@goneall, rebased and ready to merge! :)

@goneall
Copy link
Member

goneall commented Dec 13, 2021

@seabass-labrax That worked - thanks!

@goneall goneall merged commit ff23ac2 into spdx:master Dec 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants