Skip to content

Open CVEs found using sbt dependencyCheck and yarn audit #1561

@hdalsania

Description

@hdalsania

Description

This issue is created from v1.5.0 release feedback provided by Steve Lawrence.

usage [MINOR] no open CVEs found using sbt dependencyCheck and yarn audit
- MEDIUM finding for java commons-io 2.10.0 (CVE-2024-47554)
- HIGH finding for java logback-core/classic 1.2.11 (CVE-2023-6378)
- other jar dependencies seem to be false positives
- LOW finding for npm cookie

Steps to Reproduce

sbt dependencyCheck and yarn audit

Expected Behavior

should not have any medium or high vulnerability exists.

Metadata

Metadata

Assignees

Labels

bugSomething isn't working

Type

No type

Projects

Status

In Progress

Relationships

None yet

Development

No branches or pull requests

Issue actions