Skip to content

Fix vulnerable Dokka transitive dependencies - #16

Open
laurenshareshian wants to merge 1 commit into
mainfrom
laurenshareshian/fossafixes
Open

Fix vulnerable Dokka transitive dependencies#16
laurenshareshian wants to merge 1 commit into
mainfrom
laurenshareshian/fossafixes

Conversation

@laurenshareshian

Copy link
Copy Markdown
Collaborator

This addresses FOSSA findings in Dokka’s build-only dependency graph. Upgrading Dokka to 2.2.0 fixes the vulnerable Woodstox version, but doesn't fix vulnerable Jackson 2.15.3 and jsoup 1.16.1.

The change therefore also aligns Jackson through the 2.22.1 BOM and adds jsoup 1.23.1 to Dokka’s runtime configuration. No dependency forcing is used. Tests and documentation generation pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant