-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade okio-jvm dependency to atleast 3.1.0 #1457
Comments
this one comes from fabric8 project, I think the issue should be raised there and we can upgrade at some point in time or may be they backport to a minor version. Would you want to raise it over there also please? |
Thank you! I think this is the right place? |
yup! that's the one, thank you. |
This one was fixed in fabric8 library and will be delivered in |
this can only go in the next major release, since it contains breaking changes. I will maintain the PR until the major release will see daylight |
this proved to be a bit more complicated then a simple upgrade, see this issue |
The version of okio-jvm used (3.0.0) in
spring-cloud-kubernetes-client-config
is vulnerable to a ddos attack. The fix is in 3.1.0.Fixed here: square/okio#1280
The text was updated successfully, but these errors were encountered: