Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

break dependency on outdated log4j #123

Open
MFTabriz opened this issue Jul 6, 2023 · 0 comments
Open

break dependency on outdated log4j #123

MFTabriz opened this issue Jul 6, 2023 · 0 comments

Comments

@MFTabriz
Copy link

MFTabriz commented Jul 6, 2023

Currently, we ship a version of vnu.jar which uses log4j v1.2.17 and commons-fileupload v1.3.1 both of which have severe (probably irrelevant) vulnerabilities. This is preventing automatic deployment of html5validator in secure environments. As the upstream maintainers do not want to update their log4j dependency, we have to either patch it locally or drop the dependency on vnu.jar.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant