Skip to content

Fix vulnerabilities mentioned by Checkmarx used across the jmeter-java-dsl #271

Answered by rabelenda
nmelnic asked this question in General
Discussion options

You must be logged in to vote

Hello, thank you for asking and running the check.

We use snyk for scanning vulnerabilities and have no plans to change it to something else unless there is a clear reason. That being said, there are several changes pending to be appliend, in particular there is an update of jmeter dependency which is the main dependency that includes all such potentially vulnerable packages, but updating to such version requires several changes.

We will review what is the best course of action, I think updating JMeter should be the way to go even though it may require more effort than just updating vulnerable dependencies.

Regarding plan: we don't have a fixed date for solving the mentioned issue, but if…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by nmelnic
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants