Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Okio CVE-2023-3635 #10456

Closed
skjolber opened this issue Aug 7, 2023 · 2 comments
Closed

Okio CVE-2023-3635 #10456

skjolber opened this issue Aug 7, 2023 · 2 comments
Labels

Comments

@skjolber
Copy link

skjolber commented Aug 7, 2023

Okio seems to be flagged by CVE-2023-3635 and current the proposed fix is to upgrade to >= 3.4. As far as I can see this project uses version 2.10.0.

Is the project already compatible with Okio 3.x, and/or any chance of moving to Okio 3.x in the near future?

@ejona86
Copy link
Member

ejona86 commented Aug 7, 2023

To my knowledge we are already compatible with okio 3. So if you just depend on the newer version things are expected to work. I know of regular testing using okio version 3.1.0, but it also compiles against 3.1.0. So the only possible issue would be an ABI issue, which would error loudly.

Our last last release was on the last okio 1.x release. Our 1.58 release in a month should upgrade to 2.10. We tried to upgrade further, but need to spend more time fighting our build (#10359 (comment)) due to okio's published Gradle Module Metadata.

We were sitting on okio 1.x to avoid the Kotlin dependency and because we were compatible with newer versions so we wouldn't be holding anyone else back. But yeah, that CVE was cause to move forward.

@temawi
Copy link
Contributor

temawi commented Aug 11, 2023

I think the question has been answered so I'll close the issue. Feel free to re-open if needed.

@temawi temawi closed this as completed Aug 11, 2023
@github-actions github-actions bot locked as resolved and limited conversation to collaborators Nov 10, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

No branches or pull requests

3 participants